← Back to search

CVE-2026-14465

6.5 MEDIUM

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
This flaw allows session IDs to be reused, enabling attackers to replay sessions and potentially gain unauthorized access.
Exploitability
Exploitation requires knowledge of session IDs and network access; preconditions include active user sessions.
Blast radius
If exploited, it could lead to data breaches or unauthorized actions by attackers.
Prioritized remediation
Update to HUMANIST Digital Human Resources version 26.1 or later to address the issue.
session-replayauth-bypassweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-613

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.