Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper limitation of a pathname to a restricted directory, known as path traversal. It allows an attacker to construct file paths that escape the intended directory and retrieve arbitrary files from the server. The impact is the loss of confidentiality through unauthorized file download, potentially exposing sensitive data contained on the host.

Affected Systems

Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources is affected. All installations with version 26.0 or earlier contain the flaw; the issue is fixed in version 26.1 and later.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate severity vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote, via a web request to the application. An attacker would need to manipulate a file path in a request to the vulnerable component; authentication requirements are not specified in the data, so the risk remains uncertain but potentially high given the ability to download any file.

Generated by OpenCVE AI on August 4, 2026 at 20:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HUMANIST Digital Human Resources to version 26.1 or later to remove the path traversal flaw.
  • Restrict the web server or application environment so that the directory containing the vulnerable component is not readable by external users, mitigating the impact of any remaining traversal attempts.
  • Configure a web application firewall or equivalent filtering to block request paths containing traversal patterns such as '..' or URL‑encoded equivalents, providing an additional defense in depth.

Generated by OpenCVE AI on August 4, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:13:51.301Z

Reserved: 2026-06-30T08:55:32.776Z

Link: CVE-2026-14194

cve-icon Vulnrichment

Updated: 2026-08-04T13:13:43.629Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:31.927

Modified: 2026-08-04T14:16:30.257

Link: CVE-2026-14194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')