logo

Critical 9.8 CVSS Flaw in Pharos Mosaic Controllers Grants Root Access to Unauthenticated Attackers

ID: 3076566c-4d20-5d1d-aa58-4cdb031aefc9

STIX ID: report--3076566c-4d20-5d1d-aa58-4cdb031aefc9

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-27

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA and Pharos Controls published an advisory for CVE-2026-2417, a critical (CVSS 9.8) "Missing Authentication for Critical Function" vulnerability in Mosaic Show Controller firmware 2.15.3 that allows unauthenticated remote attackers to execute arbitrary commands as root; administrators are urged to upgrade to firmware 2.16 or later and to ensure controllers are not exposed directly to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.