CVE-2026-27181: Missing Authorization in sergejey MajorDoMo
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execution, making all mode-gated code paths reachable without authentication via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which deletes module records from the database, executes the module's uninstall() method via eval(), recursively deletes the module's directory and template files using removeTree(), and removes associated cycle scripts. An attacker can iterate through module names and wipe the entire MajorDoMo installation with a series of unauthenticated GET requests.
AI Analysis
Technical Summary
CVE-2026-27181 is a missing authorization vulnerability in the MajorDoMo platform's market module. The admin() method reads the 'mode' parameter from $_REQUEST and assigns it to an internal variable without verifying authentication, making all mode-restricted functions accessible without credentials via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which removes module database records, executes the module's uninstall() method via eval(), deletes module directories and templates recursively, and removes related cycle scripts. An attacker can exploit this to uninstall any module or wipe the entire MajorDoMo installation by iterating through module names with unauthenticated GET requests.
Potential Impact
An unauthenticated attacker can fully uninstall arbitrary modules, including executing uninstall scripts and deleting module files and database records. This can lead to complete destruction of the MajorDoMo installation, causing denial of service and loss of functionality. The vulnerability has a CVSS 4.0 base score of 8.7, indicating high severity with network attack vector, no required privileges or user interaction, and high impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the /objects/?module=market endpoint and monitor for suspicious unauthenticated requests targeting module uninstallation. Consider implementing network-level access controls or web application firewall rules to block unauthorized access to this functionality.
CVE-2026-27181: Missing Authorization in sergejey MajorDoMo
Description
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execution, making all mode-gated code paths reachable without authentication via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which deletes module records from the database, executes the module's uninstall() method via eval(), recursively deletes the module's directory and template files using removeTree(), and removes associated cycle scripts. An attacker can iterate through module names and wipe the entire MajorDoMo installation with a series of unauthenticated GET requests.
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-27181 is a missing authorization vulnerability in the MajorDoMo platform's market module. The admin() method reads the 'mode' parameter from $_REQUEST and assigns it to an internal variable without verifying authentication, making all mode-restricted functions accessible without credentials via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which removes module database records, executes the module's uninstall() method via eval(), deletes module directories and templates recursively, and removes related cycle scripts. An attacker can exploit this to uninstall any module or wipe the entire MajorDoMo installation by iterating through module names with unauthenticated GET requests.
Potential Impact
An unauthenticated attacker can fully uninstall arbitrary modules, including executing uninstall scripts and deleting module files and database records. This can lead to complete destruction of the MajorDoMo installation, causing denial of service and loss of functionality. The vulnerability has a CVSS 4.0 base score of 8.7, indicating high severity with network attack vector, no required privileges or user interaction, and high impact on availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the /objects/?module=market endpoint and monitor for suspicious unauthenticated requests targeting module uninstallation. Consider implementing network-level access controls or web application firewall rules to block unauthorized access to this functionality.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-02-18T15:22:30.054Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69962e786aea4a407ae9220d
Added to database: 02/18/2026, 21:26:16 UTC
Last enriched: 06/24/2026, 15:07:40 UTC
Last updated: 09/10/2026, 19:36:53 UTC
Views: 168
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.