---
id: CVE-2024-6127
title: >-
  BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that
  can lead to remote code execution
summary: >-
  BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that
  can lead to remote code execution. A remote, unauthenticated attacker can
  exploit this vulnerability over HTTP by acting as a normal agent, completing
  all crypt…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-434
published: '2024-06-27'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-6127'
references:
  - url: 'https://aceresponder.com/blog/exploiting-empire-c2-framework'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ACE-Responder/Empire-C2-RCE-PoC'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/BC-SECURITY/Empire/blob/8283bbc77250232eb493bf1f9104fdd0d468962a/CHANGELOG.md?plain=1#L102
    label: disclosure@vulncheck.com
  - url: 'https://vulncheck.com/advisories/empire-unauth-rce'
    label: disclosure@vulncheck.com
  - url: 'https://aceresponder.com/blog/exploiting-empire-c2-framework'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/ACE-Responder/Empire-C2-RCE-PoC'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/BC-SECURITY/Empire/blob/8283bbc77250232eb493bf1f9104fdd0d468962a/CHANGELOG.md?plain=1#L102
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vulncheck.com/advisories/empire-unauth-rce'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.10346
epssPercentile: 0.95555
ingestedAt: '2026-07-14T23:40:05.059Z'
exploits:
  metasploit:
    - exploit/linux/http/empire_skywalker
  checkedAt: '2026-09-26T09:05:31.842Z'
exploitAvailable: true
---

## Overview

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
