CVE-2026-31049 Details
Description
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
A vulnerability in HostBill versions through 2025-11-24 and 2025-12-01 allows remote attackers to execute arbitrary code and escalate privileges. This issue arises from a lack of proper server-side validation in the admin panel, particularly in the client import feature that accepts CSV files. Administrators can bypass mandatory registration field requirements, leading to the creation of invalid or incomplete client records. Additionally, the vulnerability can be exploited by manipulating registration field configuration requests to modify or bypass restrictions on essential fields such as username, email, and password.
Users are advised to update HostBill to the latest version, available through the Microsoft Update Catalog.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 14, 2026CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.hostbillapp.com/2025/12/03/hostbill-security-advisory/ | [email protected] | AdvisoryRemedyVendor |
| https://github.com/Muhammad5235/HostBill-CVEs-2025/blob/main/Missing%20Server-Side%20Validation/Registration%20fields%20%26%20Import%20Csv | [email protected] | ExploitTechnical Analysis |
| https://hostbillapp.com/changelog | [email protected] | Release NotesVendor |
| https://hostbillapp.com/release-notes/11-27-2025.html | [email protected] | Release NotesVendor |
| https://hostbillapp.com/release-notes/12-01-2025.html | [email protected] | Release NotesVendor |
| https://hostbillapp.com/responsible-disclosure | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1236 | Improper Neutralization of Formula Elements in a CSV File | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| HostBill | >= 2025-11-24, <= 2025-12-01 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | New CVE Received | [email protected] |
Volerion