VYPR
Unrated severityNVD Advisory· Published Feb 12, 2026· Updated Feb 13, 2026

emp3r0r Agent-Controlled Metadata to Operator RCE (tmux Command Injection)

CVE-2026-26068

Description

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command strings executed via /bin/sh -c. This enables command injection and remote code execution on the operator host. This vulnerability is fixed in 3.21.1.

Affected products

1
  • jm33-m0/emp3r0rv5
    Range: < 3.21.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.