Description
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Bilin Software’s HUMANIST Digital Human Resources allows an attacker to determine valid usernames by observing differences in login responses. The weakness is rooted in CWE‑204, where application logic exposes information through varying responses. A successful exploit provides an attacker with a list of existing accounts, potentially aiding subsequent credential‑guessing or social‑engineering attacks, and thereby compromising confidentiality of user data.

Affected Systems

Bilin Software and Informatics Consultancy Inc. offer the HUMANIST Digital Human Resources product. Versions from 26.0 through just before 26.1 are affected. Users operating these releases are potentially vulnerable to account enumeration.

Risk and Exploitability

With a CVSS score of 5.3 the risk is moderate; the EPSS score is not available, and KEV does not list this CVE. The likely attack vector is a network‑based, web‑application attack that exploits the login page. An attacker can send automated login requests to distinguish legitimate usernames from non‑existent ones based on response timing or content differences. The vulnerability requires no special privileges and can be triggered from any remote machine with network access to the application interface.

Generated by OpenCVE AI on August 4, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HUMANIST Digital Human Resources to version 26.1 or later to remove the response discrepancy that allows username enumeration.
  • Configure the application to return identical error messages for all invalid login attempts, thereby eliminating the differential response.
  • Implement rate limiting or an account lockout policy on login attempts to reduce the feasibility of automated enumeration attacks.

Generated by OpenCVE AI on August 4, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T12:52:33.191Z

Reserved: 2026-06-30T09:20:29.046Z

Link: CVE-2026-14202

cve-icon Vulnrichment

Updated: 2026-08-04T12:50:43.926Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:32.050

Modified: 2026-08-04T13:17:35.660

Link: CVE-2026-14202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:20:57Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy