Arbitrary Code Execution in Horilla HR and CRM Software
CVE-2026-96795

8.8HIGH

Key Information:

Vendor

Horilla

Vendor
CVE Published:
25 September 2026

What is CVE-2026-96795?

In versions prior to 2.0.0 of Horilla HR and CRM software, an authentication vulnerability exists in the HorillaListView.export_data method, located in horilla_views/generic/cbv/views.py. This flaw allows an authenticated user to manipulate the POST parameters. By crafting a specific input string that is interpreted as valid Python syntax, attackers can inject executable code. Such a vulnerability can result in the execution of arbitrary operating system commands, including critically privileged commands within the context of the application's running process, potentially gaining root access in Docker deployments. The issue has been addressed and resolved in version 2.0.0.

Affected Version(s)

horilla-hr < 2.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.