{"id":"CVE-2026-14194","published":"2026-08-04T10:19:31.927","lastModified":"2026-08-04T14:16:30.257","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a path traversal vulnerability that allows attackers to access sensitive files by manipulating file paths. This matters because it can lead to unauthorized data exposure.","exploitability":"Exploitation requires knowledge of the target version and specific path traversal techniques, making it moderately difficult but feasible with proper expertise.","blast_radius":"If exploited, this could result in significant data breaches affecting sensitive HR information.","remediation":"Update to HUMANIST Digital Human Resources version 26.1 or later to address the vulnerability.","tags":["path-traversal","data-exposure","hr-system"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:05:11.058Z"}}