Vulnerability Description
emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activity, Go runtime can trigger `fatal error: concurrent map read and map write`, causing C2 process crash (availability loss). Version 3.21.2 fixes this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jm33-M0 | Emp3R0R | < 3.21.2 |
Related Weaknesses (CWE)
References
- https://github.com/jm33-m0/emp3r0r/commit/ea4d074f081dac6293f3aec38f01def5f08d5aPatch
- https://github.com/jm33-m0/emp3r0r/releases/tag/v3.21.2ProductRelease Notes
- https://github.com/jm33-m0/emp3r0r/security/advisories/GHSA-f5p9-j34q-pwccExploitVendor Advisory
FAQ
What is CVE-2026-26201?
CVE-2026-26201 is a vulnerability with a CVSS score of 7.5 (HIGH). emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activi...
How severe is CVE-2026-26201?
CVE-2026-26201 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26201?
Check the references section above for vendor advisories and patch information. Affected products include: Jm33-M0 Emp3R0R.