Description
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits attackers to inject malicious SQL through the query console, enabling arbitrary SQL execution and direct access to database contents. Because the system stores sensitive information in cleartext, exploitation can result in the disclosure of confidential employee and organizational data. This weakness is identified as CWE‑312, reflecting improper handling of sensitive data during transmission or storage.

Affected Systems

Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources product, versions 26.0 up to but not including 26.1, are affected. The CVE specifically identifies version 26.0 as vulnerable; earlier releases are not explicitly confirmed as impacted.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as Critical, indicating a high potential for widespread data loss. The EPSS score is reported as < 1 %, suggesting a low but non‑zero probability of exploitation. Because the flaw involves remote execution of arbitrary SQL via the query console, an attacker with network access to the application could potentially extract sensitive data stored in cleartext. The vulnerability is not listed in the CISA KEV catalog, supporting the lack of public exploitation reports but not eliminating risk. The combination of a severe CVSS score, a possibly accessible query console, and cleartext storage makes the flaw highly actionable for attackers who can reach the console.

Generated by OpenCVE AI on August 4, 2026 at 20:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 26.1 or later to apply the vendor‑supplied fix that blocks SQL injection and eliminates cleartext storage.
  • If an upgrade is not immediately possible, restrict or disable the query console or enforce strict access controls to remove the injection vector.
  • Encrypt sensitive database fields at rest to mitigate exposure if an attacker extracts data.

Generated by OpenCVE AI on August 4, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:20:58.757Z

Reserved: 2026-07-14T12:35:05.467Z

Link: CVE-2026-15721

cve-icon Vulnrichment

Updated: 2026-08-04T13:20:53.363Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:32.667

Modified: 2026-08-04T14:16:30.620

Link: CVE-2026-15721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:10Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information