Skip to finding
important · Remote code execution

A Virtualizor billing callback can turn an unauthenticated request into root execution on the hypervisor.

Affects

Softaculous Virtualizor, a Linux-hosted VPS and hypervisor control panel whose administrative web process runs as root.

The path requires exposed administrative ports, in-house billing and an eligible suspended account. MySQL coerces the numeric prefix of a shell-bearing uid while the original string survives into a command executed by the root PHP-FPM pool.

Detail and 2 sources

A public exploit module exists, and a researcher retested the vendor fixes on September 20. The fix was not read for this brief, so the item cannot lead.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026