A critical (CVSS 9.8) unrestricted file upload flaw in Bilin Software's HUMANIST Digital Human Resources platform lets a remote, unauthenticated attacker upload a web shell to the server.
What Is It
CVE-2026-14175 is an unrestricted upload of file with dangerous type vulnerability (CWE-434) in Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources product. The flaw allows an attacker to upload a web shell to a web server.
The CVE was published on 2026-08-04 and is currently in "Received" status in NVD. It was assigned by USOM ([email protected]), Turkey's national CERT.
Why It Matters
The CVSS 3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability dimension is maximally favorable to an attacker:
- Network attack vector: reachable remotely, no local access needed
- Low attack complexity: no special conditions required
- No privileges required: unauthenticated
- No user interaction: no phishing or click needed
Impact is HIGH across confidentiality, integrity, and availability. A successful web shell upload gives an attacker code execution on the host. The specific data at risk in any given deployment is not described in the NVD record, but HR platforms of this type typically process employee personal data, payroll records, and identity documents, so that category of exposure is the plausible worst case.
This CVE does not appear in the supplied CISA Known Exploited Vulnerabilities (KEV) data, so there is no confirmation of active exploitation at this time. The KEV entry supplied was empty. Readers can check the current status directly against CISA's live catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
What's Vulnerable
| Field | Value |
|---|---|
| Vendor | Bilin Software and Informatics Consultancy Inc. |
| Product | HUMANIST Digital Human Resources |
| Affected | from 26.0 before 26.1 |
| Default status | unaffected (other versions) |
No CPE identifiers were published in the NVD record.
Patch Status
The version range indicates the issue is resolved in 26.1. Organizations running HUMANIST Digital Human Resources 26.0 should upgrade to 26.1 or later. No CISA KEV due date or required action was supplied, as the CVE is not present in the provided KEV feed.
Sources
- NVD, CVE-2026-14175: https://nvd.nist.gov/vuln/detail/CVE-2026-14175
- USOM (Turkish National CERT), referenced advisory TR-26-0737, not independently verified at time of writing: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog