AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-14175

CRITICAL · CVSS 9.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

HUMANIST Digital Human Resources versions prior to 26.1 are vulnerable to an unrestricted file upload flaw, allowing attackers to upload malicious web shells to the server. This critical vulnerability (CVSS 9.8) can lead to full server compromise, enabling unauthorized access and potential data breaches. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-14175
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%

Original NVD Description

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.