Skip to content

[New Module Request] CVE-2026-27174 #1602

Description

@Aarush289

Add a detection module for CVE-2026-27174 (MajorDoMo unauthenticated RCE, CVSS 10.0) — an unauthenticated attacker can execute arbitrary PHP via the admin console's op=console&command= endpoint due to a missing post-redirect exit. Detection: fingerprint MajorDoMo, then verify code execution by reading /etc/passwd via the console endpoint and matching root:[x*]:0:0: in the response.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions