SYS::ONLINE
Wasteland.
Briefs1691
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-14175 2026-08-04

CVE-2026-14175: Unauthenticated Web Shell Upload in HUMANIST Digital HR

"A critical (CVSS 9.8) unrestricted file upload flaw in Bilin Software's HUMANIST Digital Human Resources platform lets a remote, unauthenticated attacker upload a web shell to the server."

A critical (CVSS 9.8) unrestricted file upload flaw in Bilin Software's HUMANIST Digital Human Resources platform lets a remote, unauthenticated attacker upload a web shell to the server.

What Is It

CVE-2026-14175 is an unrestricted upload of file with dangerous type vulnerability (CWE-434) in Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources product. The flaw allows an attacker to upload a web shell to a web server.

The CVE was published on 2026-08-04 and is currently in "Received" status in NVD. It was assigned by USOM ([email protected]), Turkey's national CERT.

Why It Matters

The CVSS 3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability dimension is maximally favorable to an attacker:

Impact is HIGH across confidentiality, integrity, and availability. A successful web shell upload gives an attacker code execution on the host. The specific data at risk in any given deployment is not described in the NVD record, but HR platforms of this type typically process employee personal data, payroll records, and identity documents, so that category of exposure is the plausible worst case.

This CVE does not appear in the supplied CISA Known Exploited Vulnerabilities (KEV) data, so there is no confirmation of active exploitation at this time. The KEV entry supplied was empty. Readers can check the current status directly against CISA's live catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

What's Vulnerable

Field Value
Vendor Bilin Software and Informatics Consultancy Inc.
Product HUMANIST Digital Human Resources
Affected from 26.0 before 26.1
Default status unaffected (other versions)

No CPE identifiers were published in the NVD record.

Patch Status

The version range indicates the issue is resolved in 26.1. Organizations running HUMANIST Digital Human Resources 26.0 should upgrade to 26.1 or later. No CISA KEV due date or required action was supplied, as the CVE is not present in the provided KEV feed.

Sources