/Vulnerability Library

MajorDoMo - Unauthenticated RCE

CVE-2026-27174
Verified

Description

MajorDoMo contains a remote code execution caused by an include order bug and lack of exit after redirect in admin panel's PHP console, letting unauthenticated attackers execute arbitrary PHP code via crafted GET requests.

Severity

Critical

CVSS Score

10

Exploit Probability

5%

Affected Product

majordomo

Published Date

April 20, 2026

Template Author

0x_akoko

CVE-2026-27174.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE ID:
cve-2026-27174
CWE ID:
cwe-94

References

https://nvd.nist.gov/vuln/detail/CVE-2026-27174https://github.com/sergejey/majordomo/issues/1177https://chocapikk.com/posts/2026/majordomo-revisitedhttps://www.vulncheck.com/advisories/majordomo-unauthenticated-remote-code-execution-via-admin-console-eval

Remediation Steps

Update to the latest version with the fix for the include order bug and proper exit after redirect.