CVE-2026-15721
9.8 CRITICALPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources versions before 26.1, allowing attackers to access sensitive data through unencrypted storage and execute malicious SQL commands.
- Exploitability
- Exploitation requires access to the affected application's database or network traffic interception; preconditions include the presence of sensitive information stored in cleartext.
- Blast radius
- If exploited, this vulnerability could lead to unauthorized data exposure, system compromise, and potential loss of confidentiality and integrity of sensitive HR data.
- Prioritized remediation
- Update HUMANIST Digital Human Resources to version 26.1 or later to mitigate the SQL Injection risk and ensure secure storage of sensitive information.
sql-injectiondata-exposurepatch-available
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-312
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.