CVE-2026-25760
EUVD-2026-556106.02.2026, 22:16
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and it can expose credentials, configs, and keys. This vulnerability is fixed in 1.6.11.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bishopfox | sliver | 𝑥 < 1.6.11 |
𝑥
= Vulnerable software versions