CVE-2026-2417 PUBLISHED

Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller

Assigner: icscert
Reserved: 12.02.2026 Published: 24.03.2026 Updated: 24.03.2026

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Pharos Controls
Product Mosaic Show Controller
Versions Default: unaffected
  • Version 2.15.3 is affected

Solutions

Pharos Controls recommends that users upgrade Mosaic Show Controller to version 2.16 or later.

Credits

  • James Tully reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE