OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-96795

HIGH · CVSS 8.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Horilla HR and CRM software, specifically in the `export_data` function, where user-supplied input is improperly handled, allowing for arbitrary code execution through Python's `exec()` function. This flaw can lead to the execution of operating-system commands with the application's process privileges, potentially granting root access within the Docker environment. Organizations using versions prior to 2.0.0 should prioritize patching this vulnerability to mitigate the risk of unauthorized access and system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96795
Severity
HIGH
CVSS
8.8
EPSS
0.30%
Docker

Original NVD Description

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0.