PT-2026-102506 · Sliver C2 · Sliver C2

·

CVE-2026-102507

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Sliver C2 framework versions prior to 1.7.8
Description An unhandled panic exists in the operator gRPC handler. An attacker controlling a compromised implant can crash the teamserver by returning a malformed or empty Download response. By sending zero-length or 1-3 byte data payloads through a hostile implant session, an out-of-bounds slice access is triggered in the BinaryMagic() function of the vendored Binject library. This failure propagates through the operator gRPC interceptor chain and terminates the server process, disconnecting all operators.
Recommendations Update Sliver C2 framework to version 1.7.8 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102507

Affected Products

Sliver C2