CVE-2026-43641
9.8 CRITICALPublished 2026-09-22 · Updated 2026-09-23
AI risk analysis
- Summary
- This vulnerability allows unauthenticated attackers to execute arbitrary commands as root by exploiting a flaw in the billing module handler, leading to complete control of the host and managed VPS instances.
- Exploitability
- Exploitation is relatively straightforward with specific parameter combinations, requiring unauthenticated access and deserialization of a crafted billing_data POST field.
- Blast radius
- If exploited, the attack can result in complete control over the host system and all managed VPS instances, leading to significant data loss and potential system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Softaculous Virtualizor 3.2.9 Patch 9 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
All references
- https://www.virtualizor.com/blog/virtualizor-3-2-9-launched-release-candidate-patch-9/
- https://www.virtualizor.com/blog/virtualizor-3-3-0/
- https://www.vulncheck.com/advisories/softaculous-virtualizor-os-command-injection-via-billing-module-handler
- https://www.vulncheck.com/blog/virtualizor-billing-hook-unauthenticated-root-rce
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-90822
- HIGHCVE-2026-100852PoC
- CRITICALCVE-2026-100896PoC
- CRITICALCVE-2026-101001PoC
- CRITICALCVE-2026-101072PoC
- CRITICALCVE-2026-101075PoC
- CRITICALCVE-2026-101076PoC
- CRITICALCVE-2026-102911PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.