Description
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves a hard‑coded cryptographic key embedded in the HUMANIST Digital Human Resources binary, enabling an attacker to read sensitive constants. This disclosure undermines confidentiality and may allow decryption of protected data, facilitating further compromise. The weakness is classified as CWE‑321.

Affected Systems

The affected product is Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources. Versions 26.0 and earlier are vulnerable; version 26.1 and later contain the fix.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical risk level. The EPSS score is not available, so the estimated likelihood of exploitation remains unknown, but the absence of a KEV listing does not diminish the potential severity. The attack route likely requires access to the executable, which may be local or remote depending on deployment. An adversary could extract the embedded key and use it to compromise encrypted data or impersonate legitimate users.

Generated by OpenCVE AI on August 4, 2026 at 20:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor update to version 26.1 or later, which removes the hard‑coded key.
  • If an immediate update is not possible, redeploy the application without the hard‑coded key by regenerating cryptographic keys and configuring the system to source keys from secure storage.
  • Audit all deployed binaries to verify that no additional hard‑coded secrets remain and enable runtime integrity checks to detect tampering.

Generated by OpenCVE AI on August 4, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:10:41.148Z

Reserved: 2026-07-05T23:12:07.138Z

Link: CVE-2026-14804

cve-icon Vulnrichment

Updated: 2026-08-04T13:10:34.680Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:32.417

Modified: 2026-08-04T13:17:35.893

Link: CVE-2026-14804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:03Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key