Critical 9.8 CVSS Flaw in Pharos Mosaic Controllers Grants Root Access to Unauthenticated Attackers
ID: 3076566c-4d20-5d1d-aa58-4cdb031aefc9
STIX ID: report--3076566c-4d20-5d1d-aa58-4cdb031aefc9
Feed Name: securityonline.info
Threat Score
CISA and Pharos Controls published an advisory for CVE-2026-2417, a critical (CVSS 9.8) "Missing Authentication for Critical Function" vulnerability in Mosaic Show Controller firmware 2.15.3 that allows unauthenticated remote attackers to execute arbitrary commands as root; administrators are urged to upgrade to firmware 2.16 or later and to ensure controllers are not exposed directly to the internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
