Impact
The vulnerability involves a hard‑coded cryptographic key embedded in the HUMANIST Digital Human Resources binary, enabling an attacker to read sensitive constants. This disclosure undermines confidentiality and may allow decryption of protected data, facilitating further compromise. The weakness is classified as CWE‑321.
Affected Systems
The affected product is Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources. Versions 26.0 and earlier are vulnerable; version 26.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical risk level. The EPSS score is not available, so the estimated likelihood of exploitation remains unknown, but the absence of a KEV listing does not diminish the potential severity. The attack route likely requires access to the executable, which may be local or remote depending on deployment. An adversary could extract the embedded key and use it to compromise encrypted data or impersonate legitimate users.
OpenCVE Enrichment