Critical severity9.8NVD Advisory· Published Apr 14, 2026· Updated Apr 27, 2026
CVE-2026-31049
CVE-2026-31049
Description
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- blog.hostbillapp.com/2025/12/03/hostbill-security-advisory/nvd
- github.com/Muhammad5235/HostBill-CVEs-2025/blob/main/Missing%20Server-Side%20Validation/Registration%20fields%20%26%20Import%20Csvnvd
- hostbillapp.com/changelognvd
- hostbillapp.com/release-notes/11-27-2025.htmlnvd
- hostbillapp.com/release-notes/12-01-2025.htmlnvd
- hostbillapp.com/responsible-disclosurenvd
News mentions
0No linked articles in our index yet.