Critical unauthenticated RCE in VirtueMart core

Started by d0ublezer0, September 08, 2026, 21:32:07 PM

Previous topic - Next topic

d0ublezer0

Hi everyone,

I found a critical, unauthenticated remote code execution vulnerability in VirtueMart core — confirmed present in the current release (4.6.4 "Eagle owl"), affecting every up-to-date VirtueMart installation, not just outdated ones. A single unauthenticated GET request is enough, no login, no CSRF token.

I reported this privately to Milbo in late August specifically to avoid publishing a working exploit before a fix ships. It's now been over a week with no response.

Given the severity — this is being actively exploited in the wild, we lost a production site to it — I don't think it's responsible to keep sitting on it silently while waiting indefinitely. I'd like to escalate this to the VirtueMart core team directly rather than post exploit details here.

Could someone from the core team reach out so I can share the full technical write-up, proof of concept, and a suggested fix directly? I'm still not looking to go public with the details — just need this in front of someone who can act on it.

Thanks

d0ublezer0

Anyone? Guys, there's a serious security issue that could allow anyone to hack a site running VM—it happened to me. Who on the dev team can I contact? Milbo isn't replying, and I don't know anyone else who's actually part of the team. Also, I think I picked the wrong forum section to ask this.

sirius

J5.4.8 | PHP 8.4.23 + Redis + Opcode
Litespeed | MariaDB 10.6.28
VM Prod : 4.8.4 11374 | VM Test : 4.9.3 11254

Ghost

Is this issue still present in 4.8.2.11343? And have you tried contacting on "Discord" (https://forum.virtuemart.net/index.php?board=142.0)? It's the main communication platform for VM development now.