CVE-2026-43643
Received Received - Intake

Authorization Bypass in Virtualizor Billing Module

Vulnerability report for CVE-2026-43643, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: VulnCheck

Description

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafted act and from_billing_module parameters to the admin panel dispatcher. Attackers can send a POST request with arbitrary uid and balance values in the billing_data field to trigger an unauthenticated parameterized UPDATE against the users table, enabling account balance manipulation and potential automated service suspension for targeted accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
softaculous virtualizor to 3.2.9 (exc)
softaculous virtualizor to 3.2.9|end_excluding=3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Softaculous Virtualizor versions before 3.2.9 (Patch 9) and 3.0.0. It allows unauthenticated remote attackers to modify any tenant's account balance by sending crafted parameters to the admin panel dispatcher. Attackers can manipulate account balances by sending a POST request with arbitrary user ID and balance values, triggering an unauthenticated UPDATE against the users table.

Detection Guidance

To detect this vulnerability, monitor for unauthorized POST requests to the admin panel dispatcher with crafted act and from_billing_module parameters. Check for unexpected changes in user account balances or unusual billing_data fields in database queries.

Impact Analysis

This vulnerability could allow attackers to modify account balances, potentially leading to unauthorized financial transactions or automated service suspensions for targeted accounts. Since it requires no authentication, any exposed Virtualizor instance could be exploited remotely.

Mitigation Strategies

Immediately update Virtualizor to version 3.2.9 (Patch 9) or 3.0.0 or later. If immediate patching is not possible, restrict access to the admin panel dispatcher and review database logs for suspicious billing_data modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-43643. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart