Description
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to upload arbitrary files, including web shells, to the server without any restriction on the file type. This flaw enables remote code execution, giving an attacker full control of the application or underlying server, potentially compromising confidentiality, integrity, and availability of the entire system.

Affected Systems

Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources is affected. The issue applies to all versions prior to 26.1, including the 26.0 release.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is considered critical. The EPSS score is not provided, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web upload interface, where the attacker can directly upload a malicious file. The absence of server‑side validation allows the uploaded file to be executed by the web server, leading to a breakdown of all security controls.

Generated by OpenCVE AI on August 4, 2026 at 20:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HUMANIST Digital Human Resources to version 26.1 or newer; the latest release contains the fix for this file‑upload flaw.
  • Implement strict file‑type validation on the server side and reject any files that have executable or script extensions; rely on MIME type checks and content scanning as an additional layer.
  • Configure the upload directories with no‑execute permissions, enforce the principle of least privilege for web server processes, and enable monitoring or logging of upload activity to detect and respond to anomalous uploads.

Generated by OpenCVE AI on August 4, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:46:16.138Z

Reserved: 2026-06-30T07:35:22.008Z

Link: CVE-2026-14175

cve-icon Vulnrichment

Updated: 2026-08-04T13:46:09.360Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:31.633

Modified: 2026-08-04T14:16:30.147

Link: CVE-2026-14175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:08Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type