CVE-2026-27181: MajorDoMo Unauthenticated Module Uninstall via Market Endpoint
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execution, making all mode-gated code paths reachable without authentication via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which deletes module records from the database, executes the module's uninstall() method via eval(), recursively deletes the module's directory and template files using removeTree(), and removes associated cycle scripts. An attacker can iterate through module names and wipe the entire MajorDoMo installation with a series of unauthenticated GET requests.
Security readout for executives and security teams
Plain-English summary
CVE-2026-27181 lets an unauthenticated attacker trigger MajorDoMo module uninstallation through the market module. The reported impact is destructive: modules, related files, templates, records, and cycle scripts can be removed, potentially disabling the installation. Treat internet-exposed MajorDoMo systems as high urgency until vendor guidance is confirmed.
Executive priority
Prioritize this as a near-term availability risk for any exposed smart-home or automation deployments. The likely business impact is service disruption and loss of application components, not data theft based on the provided sources.
Technical view
The market module assigns a request-controlled mode before authentication checks, making mode-gated admin code reachable through the market endpoint. The uninstall handler invokes uninstallPlugin(), removes database records, executes the module uninstall routine, recursively deletes module/template files, and removes cycle scripts. The weakness is mapped to CWE-862.
Likely exposure
Exposure is most likely on MajorDoMo instances where the market module and objects route are reachable by unauthenticated users. The source bundle lists affected version data as incomplete, with version "0" and default status unknown, so teams should validate all maintained deployments.
Exploitation context
The bundle does not cite CISA KEV listing or confirmed active exploitation. The described attack requires network access, no privileges, no user interaction, and low complexity. Public advisory details make the issue understandable, but this assessment avoids exploit instructions.
Researcher notes
Evidence supports unauthenticated reachability to destructive uninstall logic, but affected-version boundaries and final remediation status are incomplete in the bundle. Validate against the CVE record, VulnCheck advisory, researcher write-up, and upstream PR before declaring systems fixed.
Mitigation direction
Check upstream MajorDoMo guidance and the referenced fix PR before production changes.
Restrict unauthenticated internet access to MajorDoMo administrative and module-management routes.
Back up MajorDoMo files and database before remediation or exposure testing.
Disable or isolate the market module if vendor guidance supports doing so.
Monitor for unexpected module removals, template deletion, or cycle script disappearance.
Validation and detection
Inventory all MajorDoMo instances and identify externally reachable deployments.
Confirm whether the market module is installed and exposed to unauthenticated users.
Review application logs for suspicious module-management activity before patching.
Compare installed code with the referenced upstream fix PR status.
Verify backups can restore modules, templates, database records, and cycle scripts.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-862: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-862 · source CWE mapping
Missing Authorization
Missing Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.