VYPR
Critical severity9.9NVD Advisory· Published Feb 12, 2026· Updated Jun 17, 2026

CVE-2026-26068

CVE-2026-26068

Description

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command strings executed via /bin/sh -c. This enables command injection and remote code execution on the operator host. This vulnerability is fixed in 3.21.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jm33 M0/emp3r0r2 versions
    cpe:2.3:a:jm33-m0:emp3r0r:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:jm33-m0:emp3r0r:*:*:*:*:*:*:*:*range: <3.21.1
    • (no CPE)range: <3.21.1
  • jm33-m0/emp3r0rv5
    Range: < 3.21.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.