CVE-2026-27181Disclosure(mjdm / majordomo)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execution, making all mode-gated code paths reachable without authentication via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which deletes module records from the database, executes the module's uninstall() method via eval(), recursively deletes the module's directory and template files using removeTree(), and removes associated cycle scripts. An attacker can iterate through module names and wipe the entire MajorDoMo installation with a series of unauthenticated GET requests.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • majordomo

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-19)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
majordomo

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-18: 1Mentions · 2026-02-19: 2Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 102-1802-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-192
Disclosure1General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27181 Unauthenticated Arbitrary Module Uninstallation in MajorDoMo Market Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27181

    Post summary

    The CVE-2026-27181 represents an unauthenticated arbitrary module uninstallation flaw in the MajorDoMo Market Module, with no mention of PoC, exploit code, active exploitation, or patch details.

    0001060
    4.0K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-27181 - sergejey - MajorDoMo - https://www.redpacketsecurity.com/cve-alert-cve-2026-27181-sergejey-majordomo/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-27181 #sergejey #majordomo

    Post summary

    A short CVE alert link for CVE-2026-27181 affecting MajorDoMo is shared, but the snippet lacks any technical, exploitation, or patch information.

    00000102
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27181 MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('m… https://www.cve.org/CVERecord?id=CVE-2026-27181

    Post summary

    CVE-2026-27181 allows unauthenticated users to arbitrarily uninstall modules in MajorDoMo via the market module, with no PoC, exploit, or patch mentioned.

    00000119
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmjdmmajordomo---

Explore more