CVE-2026-29781 is a medium-severity vulnerability affecting Sliver C2 server versions 1.7.3 and prior. It stems from a lack of nil-pointer validation in the Protobuf unmarshalling logic, allowing an authenticated actor with captured implant credentials to trigger a runtime panic by omitting nested fields in a signed message. This results in a global process termination for mTLS, WireGuard, and DNS transports, requiring a manual server restart. While requiring post-authentication access, this flaw acts as an infrastructure "kill-switch" for the C2 framework. There are no publicly available patches, active exploits, or community discussion at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.3CPE matchmatch criteria | cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.