{"id":"CVE-2026-43641","published":"2026-09-22T18:17:14.357","lastModified":"2026-09-23T16:16:43.407","description":"Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://www.virtualizor.com/blog/virtualizor-3-2-9-launched-release-candidate-patch-9/","tags":[]},{"url":"https://www.virtualizor.com/blog/virtualizor-3-3-0/","tags":[]},{"url":"https://www.vulncheck.com/advisories/softaculous-virtualizor-os-command-injection-via-billing-module-handler","tags":[]},{"url":"https://www.vulncheck.com/blog/virtualizor-billing-hook-unauthenticated-root-rce","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthenticated attackers to execute arbitrary commands as root by exploiting a flaw in the billing module handler, leading to complete control of the host and managed VPS instances.","exploitability":"Exploitation is relatively straightforward with specific parameter combinations, requiring unauthenticated access and deserialization of a crafted billing_data POST field.","blast_radius":"If exploited, the attack can result in complete control over the host system and all managed VPS instances, leading to significant data loss and potential system compromise.","remediation":"Upgrade to Softaculous Virtualizor 3.2.9 Patch 9 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web","os-command-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:49:49.307Z"}}