CVE-2026-27175: MajorDoMo Command Injection in rc/index.php via Race Condition
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command string within double quotes without sanitization via escapeshellarg(). The command is inserted into a database queue by safe_exec(), which performs no sanitization. The cycle_execs.php script, which is web-accessible without authentication, retrieves queued commands and passes them directly to exec(). An attacker can exploit a race condition by first triggering cycle_execs.php (which purges the queue and enters a polling loop), then injecting a malicious command via the rc endpoint while the worker is polling. The injected shell metacharacters expand inside double quotes, achieving remote code execution within one second.
Security readout for executives and security teams
Plain-English summary
CVE-2026-27175 is a critical unauthenticated command injection issue in MajorDoMo. A remote attacker may be able to run operating-system commands through exposed web endpoints. Because the stated impact is full confidentiality, integrity, and availability compromise, internet-facing MajorDoMo systems should be treated as urgent until fixed or isolated.
Executive priority
Make this an immediate remediation item for any exposed MajorDoMo environment. The vulnerability is unauthenticated, network-reachable, and rated critical, with potential full system compromise. Priority may be lower only if MajorDoMo is not deployed or is isolated from untrusted access.
Technical view
The sources describe unsanitized user input in rc/index.php being placed into a queued command by safe_exec(), then later executed by web-accessible cycle_execs.php. The issue is classified as CWE-78 with CVSS 9.8. The described race condition enables remote code execution without authentication or user interaction.
Likely exposure
Exposure is likely limited to MajorDoMo installations with the affected web endpoints reachable by untrusted users. The provided affected version data is incomplete, listing version "0" and default status unknown, so teams should inventory all MajorDoMo deployments rather than assume non-exposure.
Exploitation context
The source bundle describes a practical unauthenticated RCE path and a low-complexity CVSS vector. It does not state known active exploitation, and KEV status is false. Treat this as high-priority due to impact and reachability, not because confirmed in-the-wild exploitation was provided.
Researcher notes
Evidence is strong for the vulnerability mechanism from the CVE description, VulnCheck advisory, third-party write-up, and linked fix PR. Evidence is incomplete on exact affected release ranges and final patched release availability, so validation should focus on code state, endpoint exposure, and vendor updates.
Mitigation direction
Check MajorDoMo vendor guidance and PR #1177 for fixed code or release status.
Remove public internet access to MajorDoMo until remediation is confirmed.
Restrict rc/index.php and cycle_execs.php to trusted management networks where feasible.
Review whether authentication or web-server controls can block untrusted endpoint access.
Plan urgent patch validation before restoring broad access.
Validation and detection
Inventory all MajorDoMo deployments and externally reachable instances.
Check whether rc/index.php and cycle_execs.php are reachable without authentication.
Compare deployed code against the changes in sergejey/majordomo PR #1177.
Review web and server logs for suspicious access to the named endpoints.
Confirm compensating access controls are enforced from untrusted networks.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-78: Command execution behavior lookup
Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
4Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-78 · source CWE mapping
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.