← Back to search

CVE-2026-43641

9.8 CRITICAL

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
This vulnerability allows unauthenticated attackers to execute arbitrary commands as root by exploiting a flaw in the billing module handler, leading to complete control of the host and managed VPS instances.
Exploitability
Exploitation is relatively straightforward with specific parameter combinations, requiring unauthenticated access and deserialization of a crafted billing_data POST field.
Blast radius
If exploited, the attack can result in complete control over the host system and all managed VPS instances, leading to significant data loss and potential system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Softaculous Virtualizor 3.2.9 Patch 9 or later.
rceauth-bypasswebos-command-injection

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.