← Back to search

CVE-2026-14175

9.8 CRITICAL

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
Allows attackers to upload a web shell by exploiting an unrestricted file upload vulnerability, leading to remote code execution.
Exploitability
Exploitation is relatively easy given the lack of restrictions on file types and can be performed by any authenticated user or attacker with access to the application interface.
Blast radius
If exploited, this could result in full control over the web server hosting the HUMANIST Digital Human Resources system, potentially leading to data theft, service disruption, and further attacks.
Prioritized remediation
Update to version 26.1 or later of the HUMANIST Digital Human Resources software immediately to address the vulnerability.
rceupload-vulnwebpatch-available

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.