AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-14838

HIGH · CVSS 7.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The HUMANIST Digital Human Resources platform versions prior to 26.1 are vulnerable to session hijacking due to the use of GET request methods that expose sensitive query strings. This flaw can allow attackers to intercept and manipulate user sessions, potentially leading to unauthorized access to sensitive information. Organizations using this software should prioritize immediate patching to mitigate the risk of exploitation.

CVE
CVE-2026-14838
Severity
HIGH
CVSS
7.4
EPSS
0.26%

Original NVD Description

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.