CVE-2026-2417
Received
Received - Intake
Missing Authentication in Pharos Mosaic Controller Enables Root Command Execution
Publication date: 2026-03-24
Last updated on: 2026-03-24
Assigner: ICS-CERT
Description
Description
A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pharos | controls_mosaic_show_controller | 2.15.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |