CVE-2026-96795

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-26: 209-26
Referenced assets2 URLs
Full discourse2 posts
  • SecNews@SecNews_GR

    Κρίσιμη ευπάθεια στη λειτουργία εξαγωγής του Horilla https://www.secnews.gr/736111/horilla-leitoyrgia-exagogis-cve-2026-96795/?fsp_sid=14973

    00000120
    7.0K followersView on X
  • CVE@CVEnew

    CVE-2026-96795 Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST para… https://www.cve.org/CVERecord?id=CVE-2026-96795

    00000785
    58.1K followersView on X

Explore more