CVE-2026-14219
Received Received - Intake

Open Redirect in HUMANIST Digital Human Resources

Vulnerability report for CVE-2026-14219, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bilin_software_and_informatics_consultancy_inc humanist_digital_human_resources From 26.0 (inc) to 26.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an open redirect issue in Bilin Software's HUMANIST Digital Human Resources software. It allows attackers to trick users into visiting malicious websites by redirecting them from a trusted source to an untrusted one, enabling phishing attacks.

Detection Guidance

Detecting open redirect vulnerabilities typically involves checking web application logs for unusual URL patterns or user inputs that redirect to untrusted domains. Manually test by appending different URLs to application endpoints and observing if redirects occur to external sites. Automated tools like OWASP ZAP or Burp Suite can scan for such vulnerabilities.

Impact Analysis

This vulnerability could lead to phishing attacks where users are deceived into visiting fake websites that steal credentials or install malware. Users of the affected HUMANIST Digital Human Resources software versions before 26.1 are at risk.

Compliance Impact

This vulnerability enables phishing attacks through open redirect flaws, which could lead to unauthorized data access or disclosure. Such incidents may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if exploited.

Mitigation Strategies

Update HUMANIST Digital Human Resources to version 26.1 or later to address the vulnerability. Implement input validation to ensure URLs only redirect to trusted domains. Configure web server rules to block external redirects and monitor for suspicious redirect patterns in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14219. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart