Ad

CVE-2026-34227

MEDIUM CVSS 4.0: 5.9 EPSS 0.02%
Updated Apr 03, 2026
Bishopfox
Parameter Value
CVSS 5.9 (MEDIUM)
Affected Versions before 1.7.4
Fixed In 1.7.4
Type CWE-306 (Missing Authentication for Critical Function), CWE-942
Vendor Bishopfox
Public PoC No

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser.

This issue has been patched in version 1.7.4.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Bishopfox Sliver
cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:*:*:*
1.7.4