PHP Object Injection Vulnerability in Softaculous Virtualizor Billing Module
CVE-2026-43642
Key Information:
- Vendor
Softaculous
- Status
- Vendor
- CVE Published:
- 22 September 2026
Badges
What is CVE-2026-43642?
A PHP object injection vulnerability exists in the billing module handler of Softaculous Virtualizor versions prior to 3.2.9 (Patch 9) and 3.0.0. This vulnerability allows unauthorized remote attackers to supply arbitrary serialized PHP objects for deserialization, leveraging the act parameter set to login alongside the from_billing_module field. By manipulating the billing_data POST input, attackers can utilize the unserialize() function without proper restrictions, opening pathways for remote code execution as root through available PHP object gadget chains. This issue poses significant risks for affected installations, highlighting the importance of immediate patching and monitoring.
Affected Version(s)
Virtualizor 0 < 3.2.9 (Patch 9)
Virtualizor 3.0.0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
