← Back to search

CVE-2026-14194

6.5 MEDIUM

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw is a path traversal vulnerability that allows attackers to access sensitive files by manipulating file paths. This matters because it can lead to unauthorized data exposure.
Exploitability
Exploitation requires knowledge of the target version and specific path traversal techniques, making it moderately difficult but feasible with proper expertise.
Blast radius
If exploited, this could result in significant data breaches affecting sensitive HR information.
Prioritized remediation
Update to HUMANIST Digital Human Resources version 26.1 or later to address the vulnerability.
path-traversaldata-exposurehr-system

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-22

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.