CVE-2026-27174Disclosure(mjdm / majordomo)

HIGHCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch mjdm majordomo systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to continue past a redirect() call that lacks an exit statement, allowing unauthenticated requests to reach the ajax handler in inc_panel_ajax.php. The console handler within that file passes user-supplied input from GET parameters (via register_globals) directly to eval() without any authentication check. An attacker can execute arbitrary PHP code by sending a crafted GET request to /admin.php with ajax_panel, op, and command parameters.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • majordomo

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-19); latest day: 2
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
majordomo

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 6d
01122Mentions · 2026-02-18: 1Mentions · 2026-02-19: 2Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-05-05: 2Mentions · 2026-05-07: 2PoC Mentioned / Linked · 2026-04-21: 1Exploit Tool / Code · 2026-04-20: 1Active Exploitation · 2026-04-20: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-07: 202-1802-1904-2004-2105-0505-07
Signal classification4 categories
Disclosure
666.7%
Patch
111.1%
Active Exploitation
111.1%
General
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-192
Disclosure1Patch1
2026-04-201
Active Exploitation1
2026-04-211
Disclosure1
2026-05-052
Disclosure2
2026-05-072
Disclosure1General1
Full discourse9 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    Critical MajorDoMo RCE (CVE-2026-27174): Unauthenticated Remote Code Execution Analysis https://www.resecurity.com/blog/article/critical-majordomo-rce-cve-2026-27174-unauthenticated-remote-code-execution-analysis

    Post summary

    The referenced article discloses CVE‑2026‑27174, an unauthenticated remote code execution vulnerability in MajorDoMo, and provides detailed analysis of the exploit path.

    0602092.7K
    158.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27174 - critical 🚨 MajorDoMo - Unauthenticated RCE > MajorDoMo contains a remote code execution caused by an include order bug and lack of... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27174 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-27174, describing it as a critical unauthenticated RCE in MajorDoMo and provides a link likely containing more technical details or a PoC.

    050105777
    973 followersView on X
  • Jacob Baines@Junior_Baines
    Active Exploitation

    Caught in the @VulnCheckAI canary network: attackers exploiting CVE-2026-27174 (Majordomo) with textbook Metasploit php/meterpreter/reverse_tcp payloads. Source: 146.70.124[.]214 (Romania) calling back to 51.159.195[.]33:4047

    Post summary

    The post reports real‑world exploitation of CVE‑2026‑27174 using a Metasploit module, indicating active attacks but no mention of patches or false claims.

    02031491
    3.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『MajorDoMo is important because it often acts as the central controller for an entire smart-home or automation environment.』 Critical MajorDoMo RCE (CVE-2026-27174): Unauthenticated Remote Code Execution Analysis https://www.resecurity.com/blog/article/critical-majordomo-rce-cve-2026-27174-unauthenticated-remote-code-execution-analysis

    Post summary

    The article announces a newly discovered unauthenticated RCE vulnerability (CVE‑2026‑27174) in MajorDoMo, providing analysis remarks but no PoC, exploit evidence, patch, or active exploitation claims.

    00021340
    6.9K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL RCE flaw in MajorDoMo puts home automation at risk! Unauthenticated attackers can run code remotely. European orgs: restrict access & patch ASAP. Full compromise possible if unmitigated. Details: https://radar.offseq.com/threat/cve-2026-27174-improper-control-of-gen... https://t.co/z6zT55bppz

    Post summary

    The post highlights a critical remote‑code‑execution vulnerability in MajorDoMo and urges immediate patching, with no indication of active exploitation or a proof‑of‑concept.

    1001047
    265 followersView on X
  • The Daily Tech Feed@dailytechonx
    General

    Critical RCE vulnerability (CVE-2026-27174) found in MajorDoMo smart home platform. Immediate action required to secure systems. Link: https://thedailytechfeed.com/critical-rce-vulnerability-found-in-majordomo-smart-home-platform-users-urged-to-secure-systems-immediately/ #CyberSecurity #RCE #Vulnerability #CVE2026 #MajorDoMo #SmartHome #IoT #Exploitation #Security #Patch #Mitigation #Threat #Risk #Firmware #Network #Automation #Breach #Infosec #Alert #Protection

    Post summary

    The post announces a critical RCE vulnerability (CVE-2026-27174) affecting MajorDoMo, urging immediate action, but it lacks details on patches, PoC, or exploitation evidence.

    0001079
    307 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27174 Unauthenticated Remote Code Execution in MajorDoMo Admin Panel via PHP Console https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27174

    Post summary

    The entry announces CVE-2026-27174, detailing an unauthenticated RCE vulnerability in the MajorDoMo admin panel via PHP console, but provides no PoC, exploit code, or mitigation information.

    0001056
    4.0K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    ثغرة خطيرة في MajorDoMo (CVE-2026-27174): تحليل لتنفيذ التعليمات البرمجية عن بُعد دون مصادقة. A critical vulnerability in MajorDoMo (CVE-2026-27174) has been identified, enabling unauthenticated remote code execution. Dive into the detailed analysis here: https://www.resecurity.com/blog/article/critical-majordomo-rce-cve-2026-27174-unauthenticated-remote-code-execution-analysis #CyberSecurity #VulnerabilityAnalysis #MajorDoMo

    Post summary

    A critical unauthenticated remote code execution vulnerability, CVE-2026-27174, has been identified in MajorDoMo; the post provides technical analysis but no PoC, exploit, patch, or evidence of active exploitation.

    0000046
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27174 MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.cl… https://www.cve.org/CVERecord?id=CVE-2026-27174

    Post summary

    The CVE-2026-27174 vulnerability in MajorDoMo enables unauthenticated remote code execution through the admin panel's PHP console due to an include order bug. No evidence of active exploitation, PoC, or patch information is provided.

    00000127
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmjdmmajordomo---

Explore more