CVE-2026-27180Disclosure(mjdm / majordomo)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mjdm majordomo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module exposes its admin() method through the /objects/?module=saverestore endpoint without authentication because it uses gr('mode') (which reads directly from $_REQUEST) instead of the framework's $this->mode. An attacker can poison the system update URL via the auto_update_settings mode handler, then trigger the force_update handler to initiate the update chain. The autoUpdateSystem() method fetches an Atom feed from the attacker-controlled URL with trivial validation, downloads a tarball via curl with TLS verification disabled (CURLOPT_SSL_VERIFYPEER set to FALSE), extracts it using exec('tar xzvf ...'), and copies all extracted files to the document root using copyTree(). This allows an attacker to deploy arbitrary PHP files, including webshells, to the webroot with two GET requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-494

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • majordomo

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
majordomo

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-18: 2Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-18: 202-18
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27180 MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore… https://www.cve.org/CVERecord?id=CVE-2026-27180

    Post summary

    The post announces CVE-2026-27180 in MajorDoMo, describing an unauthenticated remote code execution vulnerability via update URL poisoning, with no mention of exploits, patches, or active attacks.

    00000118
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-27180 in sergejey MajorDoMo lets attackers deploy arbitrary PHP via unauthenticated remote code execution. Patch ASAP! 🔒 https://radar.offseq.com/threat/cve-2026-27180-download-of-code-without-integrity--99709b79 #OffSeq #CVE #infosec https://t.co/KCQLBMsGsw

    Post summary

    Critical CVE-2026-27180 allows unauthenticated remote code execution in MajorDoMo, enabling arbitrary PHP deployment; urgent patching is recommended.

    0000038
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmjdmmajordomo---

Explore more