CVE-2026-27175Disclosure(mjdm / majordomo)

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mjdm majordomo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command string within double quotes without sanitization via escapeshellarg(). The command is inserted into a database queue by safe_exec(), which performs no sanitization. The cycle_execs.php script, which is web-accessible without authentication, retrieves queued commands and passes them directly to exec(). An attacker can exploit a race condition by first triggering cycle_execs.php (which purges the queue and enters a polling loop), then injecting a malicious command via the rc endpoint while the worker is polling. The injected shell metacharacters expand inside double quotes, achieving remote code execution within one second.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • majordomo

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
majordomo

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-18: 2Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-18: 202-18
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27175 MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into… https://www.cve.org/CVERecord?id=CVE-2026-27175

    Post summary

    The post announces CVE‑2026‑27175 as an unauthenticated OS command injection flaw in MajorDoMo, providing basic technical details but no PoC, exploit code, patch information, or evidence of active exploitation.

    00000127
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 MajorDoMo home automation hit by a CRITICAL OS command injection flaw (CVSS 9.2)! Unauthenticated RCE possible via rc/index.php & cycle_execs.php. Patch or restrict access now. 🏡 https://radar.offseq.com/threat/cve-2026-27175-improper-neutralization-of-special--9a0f14bf #Off... https://t.co/p2jcA37nPj

    Post summary

    The tweet reports a critical OS command injection flaw (CVE-2026-27175) in MajorDoMo with CVSS 9.2, urging users to patch or restrict access immediately.

    0000040
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmjdmmajordomo---

Explore more