PT-2026-96921 · Softaculous · Virtualizor

·

CVE-2026-43642

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Softaculous Virtualizor versions prior to 3.2.9 (Patch 9) Softaculous Virtualizor version 3.0.0
Description A PHP object injection issue exists in the billing module handler. Unauthenticated remote attackers can provide arbitrary serialized PHP objects for deserialization by setting the act parameter to login while the from billing module parameter is present. By passing malicious serialized data through the billing data POST field, the unserialize() function processes the data without allowed classes restrictions. This allows the exploitation of POP chains (Property-Oriented Programming, a technique used to execute arbitrary code by leveraging existing classes in the application) to achieve remote code execution with root privileges.
Recommendations Update to version 3.2.9 (Patch 9) or later. Update to a version newer than 3.0.0. As a temporary mitigation, restrict access to the billing module handler to prevent unauthenticated remote requests.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43642

Affected Products

Virtualizor