Junglewise Threat Intelligence

CVE-2026-43642: Softaculous Virtualizor PHP object injection in billing module

CVE-2026-43642 · Severity: high · CVSS 8.1 · Published 2026-09-22

Technologies: Softaculous Virtualizor. Vendors: Softaculous.

Executive brief

Softaculous Virtualizor is a virtualization management platform used to administer and provision cloud servers. Versions before 3.2.9 Patch 9 contain a critical flaw in the billing module that allows unauthenticated attackers to inject malicious code and execute commands as the root system user. An attacker can exploit this remotely without authentication to take over the entire server.

Technical details

The vulnerability is a PHP object injection flaw in the billing module handler triggered by the login action with from_billing_module parameter present. Attackers supply malicious serialized PHP objects via the billing_data POST field, which are deserialized without allowed_classes restrictions, enabling exploitation of POP chains to achieve remote code execution as root. No authentication is required; the attack is triggered over the network.

Affected products

  • Softaculous Virtualizor before 3.2.9 Patch 9, also 3.0.0

Timeline

  • 2026-09-22: disclosed: CVE-2026-43642 published
  • 2026-09-01: patched: Virtualizor 3.2.9 Patch 9 released

References

Related threats