CVE-2026-27181
7.5sergejey · MajorDoMo
An unauthenticated module uninstallation vulnerability exists in the MajorDoMo market module, allowing attackers to delete modules and execute arbitrary code via the uninstall() method.
Executive summary
MajorDoMo is vulnerable to unauthenticated arbitrary module uninstallation, which can lead to complete system destruction and arbitrary code execution.
Vulnerability
This is a missing authorization flaw (CWE-862) within the market module's admin() method. The application fails to verify user credentials, allowing unauthenticated attackers to invoke the uninstallPlugin() function via the /objects/?module=market endpoint.
Business impact
Successful exploitation allows an unauthenticated attacker to systematically uninstall modules, delete database records, and execute arbitrary code via the module's uninstall() method. This poses a severe risk of total system compromise, permanent data loss, and operational downtime. Given the CVSS score of 7.5, this vulnerability represents a high-severity risk that could be leveraged to disrupt critical home automation infrastructure.
Remediation
Immediate Action: Since a specific patch version is currently unavailable, restrict access to the /objects/ endpoint at the network or web server level immediately.
Proactive Monitoring: Monitor server access logs for anomalous GET requests targeting the /objects/?module=market endpoint, particularly those involving the uninstall mode.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to block or challenge all unauthenticated requests directed at the market module's administrative functions.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the technical write-up provided in the vulnerability references.
Analyst recommendation
The ability for an unauthenticated user to trigger directory traversal and code execution via the uninstall process makes this a critical priority for any organization running MajorDoMo. Administrators must implement strict access controls to the management interface immediately to prevent unauthorized module removal and potential code execution. Monitor vendor communication channels closely for the release of an official patch.
Sources
Originally found and disclosed by Valentin Lobstein, per the CVE Program record.
- MajorDoMo Revisited: What I Missed in 2023 Third-party advisory
- Fix PR: sergejey/majordomo#1177 Issue tracker
- VulnCheck Advisory: MajorDoMo Unauthenticated Module Uninstall via Market Endpoint Third-party advisory