MajorDoMo contains a remote code execution caused by an include order bug and lack of exit after redirect in admin panel's PHP console, letting unauthenticated attackers execute arbitrary PHP code via crafted GET requests.
id: CVE-2026-27174
info:
name: MajorDoMo - Unauthenticated RCE
author: 0x_Akoko
severity: cri
...