PHP Object Injection Vulnerability in Softaculous Virtualizor Billing Module
CVE-2026-43642

9.2CRITICAL

Key Information:

Vendor
CVE Published:
22 September 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-43642?

A PHP object injection vulnerability exists in the billing module handler of Softaculous Virtualizor versions prior to 3.2.9 (Patch 9) and 3.0.0. This vulnerability allows unauthorized remote attackers to supply arbitrary serialized PHP objects for deserialization, leveraging the act parameter set to login alongside the from_billing_module field. By manipulating the billing_data POST input, attackers can utilize the unserialize() function without proper restrictions, opening pathways for remote code execution as root through available PHP object gadget chains. This issue poses significant risks for affected installations, highlighting the importance of immediate patching and monitoring.

Affected Version(s)

Virtualizor 0 < 3.2.9 (Patch 9)

Virtualizor 3.0.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
VulnCheck
.