CVE-2026-43641: Softaculous Virtualizor OS Command Injection via Billing Module Handler
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billingdata POST field and inject shell payloads through the uid field, which is passed unmodified to procopen() via vexec(), yielding complete control of the host and all managed VPS instances.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Softaculous Virtualizorto a version that resolves this vulnerability.Fixed in 3.2.9Patch Patch 9
Event History
Frequently Asked Questions
Which Virtualizor versions should be treated as affected?
Softaculous Virtualizor versions before 3.2.9 Patch 9 and version 3.0.0 are identified as affected.
Does exploitation require valid credentials or user interaction?
No. The issue is described as exploitable remotely without authentication or user interaction through specific parameter combinations in the billing module handler.
What systems are at risk if exploitation succeeds?
Successful exploitation can execute commands as root on the Virtualizor host, resulting in complete control of that host and all managed VPS instances.