logo

Critical MajorDoMo RCE (CVE-2026-27174): Unauthenticated Remote Code Execution Analysis

ID: dbfcd33d-f754-5928-b3e5-26472ce13e78

STIX ID: report--dbfcd33d-f754-5928-b3e5-26472ce13e78

Feed Name: Resecurity

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-07-27

...
...

CVE-2026-27174 is a critical unauthenticated remote code execution vulnerability in the MajorDoMo home-automation platform resulting from improper authentication handling (missing exit after redirect) combined with unsafe use of PHP eval(), allowing attackers to execute arbitrary PHP via the admin AJAX console; the report includes technical details, a public Nuclei detection template and curl PoC, impact analysis on IoT/home automation, and recommended mitigations such as restricting admin access, disabling the console, and applying vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.