CVE 9.3 CRITICAL

Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller_CVE-2026-2417

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

Basic Information

ID CVE-2026-2417
Source icscert
Published Mar 24, 2026 at 18:06
Modified Mar 24, 2026 at 18:38

Affected Product

Vendor Pharos Controls
Product Mosaic Show Controller
Version 2.15.3
Affected Versions Pharos Controls Mosaic Show Controller 2.15.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.