AllCyberNews

CVE-2026-2417

Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller

CVSS 9.3 critical · Pharos Controls Mosaic Show Controller · published 2026-03-24

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

Coverage 1 source

  1. 2026-03-24 CISA Cybersecurity Advisories critical Pharos Controls Mosaic Show Controller

    Pharos Controls Mosaic Show Controller has a vulnerability allowing unauthenticated attackers to execute arbitrary commands with root privileges.

Also covered