{"id":"CVE-2026-14465","published":"2026-08-04T10:19:32.293","lastModified":"2026-08-04T13:17:35.780","description":"Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay).\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwes":["CWE-613"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows session IDs to be reused, enabling attackers to replay sessions and potentially gain unauthorized access.","exploitability":"Exploitation requires knowledge of session IDs and network access; preconditions include active user sessions.","blast_radius":"If exploited, it could lead to data breaches or unauthorized actions by attackers.","remediation":"Update to HUMANIST Digital Human Resources version 26.1 or later to address the issue.","tags":["session-replay","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:05:15.064Z"}}