Bilin Software's HUMANIST Digital Human Resources platform carries a CVSS 9.8 flaw that NVD records as cleartext storage of sensitive information (CWE-312) allowing SQL injection. The published CVSS vector rates it as network-exploitable with no privileges and no user interaction required.
What Is It
CVE-2026-15721 is a cleartext storage of sensitive information vulnerability (CWE-312) in Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources product. Per the NVD record, the weakness allows SQL Injection. The CVE was published on 2026-08-04 and is currently in "Received" status, meaning NVD analysis is still pending. It was reported by USOM, Turkey's national CERT.
The pairing of CWE-312 with a SQL injection outcome is unusual, and the record carries no technical write-up explaining the relationship between the two. Until NVD completes analysis, the precise mechanism, and which of the two weaknesses drives the CVSS score, should be treated as unsettled.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
That vector breaks down to a worst-case profile: exploitable over the network, low attack complexity, no privileges required, and no user interaction. Impact is high across all three axes, confidentiality, integrity, and availability, giving an exploitability subscore of 3.9 (the maximum) and an impact subscore of 5.9.
HR platforms concentrate personally identifiable information: payroll data, national identity numbers, employment records, and internal org structure. If the PR:N rating reflects a genuinely pre-authentication SQL injection path, an inference from the CVSS vector rather than anything stated in the advisory text, it would offer a direct route to bulk PII exposure. That worst case is worth planning against, but no public technical detail currently confirms it.
What's Vulnerable
- Vendor: Bilin Software and Informatics Consultancy Inc.
- Product: HUMANIST Digital Human Resources
- Affected versions: 26.0 up to (but not including) 26.1
All other versions are listed with a default status of unaffected. No CPE entries have been assigned in the NVD record yet, which will limit automated scanner coverage until analysis completes.
Patch Status
The affected range terminates below 26.1, which suggests the issue is resolved in that release; though the CVE record contains no vendor patch note or fix commit confirming it, and the version boundary alone is not proof of a remediated build. Operators running 26.0 through 26.0.x should plan to move to 26.1 or later, and confirm fix status directly with Bilin Software before treating the upgrade as closing the issue.
CVE-2026-15721 does not appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-08-04, so no BOD 22-01 remediation deadline applies to US federal civilian agencies. No public reporting of in-the-wild exploitation has surfaced at the time of writing, though absence of reporting is not evidence that exploitation is not occurring; particularly for a regionally deployed product where local-language reporting may lag.
Sources
- NVD, CVE-2026-15721: https://nvd.nist.gov/vuln/detail/CVE-2026-15721
- USOM (Turkish National CERT): https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737; this advisory identifier and deep link are derived from the CVE reference data and have not been independently confirmed to resolve; readers should cross-check against USOM's published advisory index.
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog