CVE-2026-27174: Improper Control of Generation of Code ('Code Injection') in sergejey MajorDoMo
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to continue past a redirect() call that lacks an exit statement, allowing unauthenticated requests to reach the ajax handler in inc_panel_ajax.php. The console handler within that file passes user-supplied input from GET parameters (via register_globals) directly to eval() without any authentication check. An attacker can execute arbitrary PHP code by sending a crafted GET request to /admin.php with ajax_panel, op, and command parameters.
AI Analysis
Technical Summary
CVE-2026-27174 affects MajorDoMo due to an include order bug in modules/panel.class.php where execution continues after a redirect() call lacking an exit statement. This flaw allows unauthenticated requests to reach inc_panel_ajax.php's ajax handler. The console handler in this file uses user-supplied GET parameters passed via register_globals directly to eval() without authentication, enabling remote code execution. An attacker can exploit this by sending crafted GET requests with ajax_panel, op, and command parameters to /admin.php, resulting in arbitrary PHP code execution.
Potential Impact
This vulnerability allows unauthenticated remote attackers to execute arbitrary PHP code on the affected MajorDoMo server. This can lead to full system compromise, data theft, service disruption, or further attacks within the network. The CVSS 4.0 score of 9.3 reflects the critical severity and ease of exploitation without any privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the admin panel and disable or restrict the PHP console feature if possible. Monitor for unusual requests targeting /admin.php with ajax_panel parameters and consider implementing web application firewall rules to block suspicious inputs.
CVE-2026-27174: Improper Control of Generation of Code ('Code Injection') in sergejey MajorDoMo
Description
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to continue past a redirect() call that lacks an exit statement, allowing unauthenticated requests to reach the ajax handler in inc_panel_ajax.php. The console handler within that file passes user-supplied input from GET parameters (via register_globals) directly to eval() without any authentication check. An attacker can execute arbitrary PHP code by sending a crafted GET request to /admin.php with ajax_panel, op, and command parameters.
CVSS v4.0
Score 9.3critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-27174 affects MajorDoMo due to an include order bug in modules/panel.class.php where execution continues after a redirect() call lacking an exit statement. This flaw allows unauthenticated requests to reach inc_panel_ajax.php's ajax handler. The console handler in this file uses user-supplied GET parameters passed via register_globals directly to eval() without authentication, enabling remote code execution. An attacker can exploit this by sending crafted GET requests with ajax_panel, op, and command parameters to /admin.php, resulting in arbitrary PHP code execution.
Potential Impact
This vulnerability allows unauthenticated remote attackers to execute arbitrary PHP code on the affected MajorDoMo server. This can lead to full system compromise, data theft, service disruption, or further attacks within the network. The CVSS 4.0 score of 9.3 reflects the critical severity and ease of exploitation without any privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the admin panel and disable or restrict the PHP console feature if possible. Monitor for unusual requests targeting /admin.php with ajax_panel parameters and consider implementing web application firewall rules to block suspicious inputs.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-02-18T15:22:30.052Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69962e786aea4a407ae921ea
Added to database: 02/18/2026, 21:26:16 UTC
Last enriched: 06/24/2026, 15:06:43 UTC
Last updated: 09/10/2026, 19:36:53 UTC
Views: 220
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.