logo

Max Severity RCE Vuln in All Versions of MITRE Caldera

ID: 1399e1e7-12d7-591b-81f0-c429babe4843

STIX ID: report--1399e1e7-12d7-591b-81f0-c429babe4843

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-02-25

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-27364) affects all versions of MITRE Caldera via its dynamic agent compilation endpoint; an attacker can inject commands when Go, Python, and gcc are present, leading to full system compromise. A PoC has been published (with planned Metasploit module), and MITRE/author recommend immediate upgrade to the master branch or v5.1.0+ and avoiding exposing Caldera servers to the Internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.