---
id: CVE-2026-43641
title: >-
  Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS
  command injection vulnerability in the billing module handler that allows
  unauthenticated remote attackers to execute arbitrary commands as root by
  bypassing authent…
summary: >-
  Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS
  command injection vulnerability in the billing module handler that allows
  unauthenticated remote attackers to execute arbitrary commands as root by
  bypassing authent…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Softaculous
product: Virtualizor
affected:
  - Virtualizor < 3.2.9 (Patch 9)
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T16:16:43.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43641'
references:
  - url: >-
      https://www.virtualizor.com/blog/virtualizor-3-2-9-launched-release-candidate-patch-9/
    label: disclosure@vulncheck.com
  - url: 'https://www.virtualizor.com/blog/virtualizor-3-3-0/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/softaculous-virtualizor-os-command-injection-via-billing-module-handler
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/blog/virtualizor-billing-hook-unauthenticated-root-rce
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-23T15:40:21.208506Z'
epss: 0.03026
epssPercentile: 0.86916
ingestedAt: '2026-09-22T18:08:12.475Z'
---

## Overview

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
