CVE-2026-14175
Received Received - Intake

Unrestricted File Upload in HUMANIST Digital Human Resources

Vulnerability report for CVE-2026-14175, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bilin_software_and_informatics_consultancy_inc humanist_digital_human_resources From 26.0 (inc) to 26.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to upload a malicious file, such as a web shell, to a web server by exploiting unrestricted file upload functionality in HUMANIST Digital Human Resources software versions before 26.1. A web shell enables remote control of the server.

Detection Guidance

Detecting this vulnerability requires checking for unrestricted file uploads in HUMANIST Digital Human Resources versions before 26.1. Inspect web server directories for unexpected files, especially web shells. Monitor network traffic for unusual outbound connections from the server.

Impact Analysis

An attacker could gain full control over the affected server, leading to data theft, unauthorized access, or disruption of services. This could compromise sensitive employee or organizational data stored in the HR system.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of personal data, violating GDPR and HIPAA requirements for data protection and confidentiality. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update HUMANIST Digital Human Resources to version 26.1 or later. Disable file uploads if not required. Implement strict file type and size restrictions. Use web application firewalls to block malicious uploads and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14175. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart