Skip to main content
Mallory
Back to intelligence
internet-facing-service-vulnerabilityembedded-device-vulnerabilitydetection-content-updatewidely-deployed-product-advisory

Critical Unauthenticated RCE in MajorDoMo Exposes IoT Management Servers

Updated 23d agoFirst seen May 5, 20262 sources

A critical vulnerability in the MajorDoMo home automation platform, tracked as CVE-2026-27174, allows unauthenticated remote code execution on internet-facing servers. The flaw stems from improper authentication handling in /admin.php, where requests continue to be processed after a redirect, combined with unsafe use of PHP eval() on attacker-controlled input in an internal AJAX console/debugging component. Researchers reported that a single crafted HTTP GET request can reach the internal handler and execute arbitrary PHP code without valid credentials.

Successful exploitation can give attackers full server compromise, including the ability to run system commands, read sensitive files, steal credentials, and deploy persistent web shells. Because MajorDoMo is often used to manage cameras, sensors, locks, and other building or home automation systems, a breach can also expose connected IoT environments and support lateral movement into internal networks. Public detection content, including a Nuclei template, is already available, raising the risk of rapid exploitation, and defenders have been urged to apply the vendor patch, restrict admin access to trusted networks, place the interface behind a VPN or authenticated reverse proxy, disable the console feature where possible, audit logs, and rotate secrets.

Share:
Critical Unauthenticated RCE in MajorDoMo Exposes IoT Management Servers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
May 6, 202624d ago

Broader reporting highlights risk to internet-facing MajorDoMo servers

Subsequent reporting emphasized that CVE-2026-27174 allows a single crafted request to execute arbitrary PHP code on exposed MajorDoMo servers, enabling actions such as command execution, file access, and web shell installation. The coverage also reiterated the risk to connected IoT and building automation environments and urged patching and access restrictions.

Apr 22, 20261mo ago

Public Nuclei detection template becomes available for CVE-2026-27174

By the time of disclosure, a public ProjectDiscovery Nuclei template existed to detect exposed MajorDoMo instances vulnerable to CVE-2026-27174. Its availability increased the likelihood of rapid identification and potential exploitation of internet-facing servers.

Resecurity discloses MajorDoMo RCE vulnerability CVE-2026-27174

Resecurity published analysis of CVE-2026-27174, a critical unauthenticated remote code execution flaw in the MajorDoMo home automation platform. The issue stems from improper authentication handling in /admin.php combined with unsafe PHP eval() use in an internal console/debugging feature.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Affected products
2 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.