Remote Code Execution Risk in emp3r0r C2 by jm33-m0
CVE-2026-61554

7.5HIGH

Key Information:

Vendor

Jm33-m0

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-61554?

The emp3r0r command-and-control (C2) framework, designed for Linux environments, has a significant vulnerability in versions prior to 4.2.5. In these versions, the http_poll transport allows unauthorized attackers to exploit HTTP polling sessions before the completion of CBOR MsgAuth authentication. This flaw enables them to create arbitrary polling sessions, sending potentially harmful requests that can consume server resources and circumvent authentication mechanisms. It is crucial for users of emp3r0r to upgrade to version 4.2.5 or later to mitigate these risks effectively.

Affected Version(s)

emp3r0r < 4.2.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.