Description
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay).

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insufficient session expiration flaw that permits session IDs to be reused, enabling session replay attacks. This flaw, classified as CWE‑613, allows an attacker to hijack or impersonate a user by capturing and reusing a valid session ID, effectively bypassing authentication mechanisms. The impact includes unauthorized access to protected resources and potential data compromise on the affected system.

Affected Systems

The flaw affects Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources application in versions prior to 26.1, specifically 26.0 and earlier.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited publicly known exploitation. The likely attack vector involves an attacker capturing a session ID through network sniffing, phishing, or other means and then reusing that ID to gain unauthorized access, potentially from within the same session context. The risk is moderate, but the lack of immediate exploitation evidence means that a vigilant monitoring stance is advisable.

Generated by OpenCVE AI on August 4, 2026 at 20:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HUMANIST Digital Human Resources to version 26.1 or later, which enforces proper session invalidation.
  • Configure the application or web server to enforce a short session timeout and require re-authentication for sensitive actions.
  • Monitor session logs for repeated usage of the same session ID and investigate any anomalies.

Generated by OpenCVE AI on August 4, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Session Fixation in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:03:45.970Z

Reserved: 2026-07-02T11:47:07.797Z

Link: CVE-2026-14465

cve-icon Vulnrichment

Updated: 2026-08-04T13:03:07.396Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:32.293

Modified: 2026-08-04T13:17:35.780

Link: CVE-2026-14465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:20:59Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration