Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances. | |
| Title | Softaculous Virtualizor OS Command Injection via Billing Module Handler | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T17:51:13.064Z
Reserved: 2026-05-01T18:22:45.642Z
Link: CVE-2026-43641
No data.
Status : Deferred
Published: 2026-09-22T18:17:14.357
Modified: 2026-09-22T20:43:58.793
Link: CVE-2026-43641
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:45:07Z
