CVE-2026-25760 describes a path traversal vulnerability in the Sliver command and control framework, specifically affecting versions prior to 1.6.11. An authenticated operator can exploit this flaw to read arbitrary files on the Sliver server host. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and can lead to the exposure of sensitive data like credentials, configurations, and keys. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog, indicating no active exploitation. However, there is some community discussion and media coverage, suggesting awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.11CPE matchmatch criteria | cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.