PT-2026-20338 · Emp3R0R · Emp3R0R

Xtle0O0

·

Published

2026-02-17

·

Updated

2026-03-03

·

CVE-2026-26201

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions emp3r0r versions prior to 3.21.2
Description The software accesses multiple shared maps without consistent synchronization across goroutines. Concurrent activity can trigger a fatal error: concurrent map read and map write, leading to a C2 process crash and resulting in availability loss. The issue stems from mixed access patterns (iteration and mutation) without a single lock policy in maps such as the operator session map, port-forwarding session map, and FTP stream map. An attacker can trigger high concurrency, such as through rapid operator session churn and simultaneous agent message traffic, to exploit this condition. This results in a denial of service as the C2 component exits due to the panic.
Recommendations Versions prior to 3.21.2 should be updated to version 3.21.2 or later.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26201
GHSA-F5P9-J34Q-PWCC
GO-2026-4504
SUSE-SU-2026:0757-1

Affected Products

Emp3R0R