CVE-2026-14175: Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources
Published Aug 4, 2026
·Updated
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Affected Software
1 affected component
Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources>=26.0<26.1
Event History
Aug 4, 2026
CVE Published
via MITRE·08:23 AM
Data Sourced
via MITRE·08:23 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14175?
The severity of CVE-2026-14175 is critical with a CVSS score of 9.8.
2
How do I fix CVE-2026-14175?
To fix CVE-2026-14175, upgrade HUMANIST Digital Human Resources to version 26.1 or later.
3
What type of vulnerability is CVE-2026-14175?
CVE-2026-14175 is classified as a malicious file upload vulnerability.
4
Which software is affected by CVE-2026-14175?
CVE-2026-14175 affects Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources versions prior to 26.1.
5
What can exploit CVE-2026-14175?
CVE-2026-14175 can be exploited to upload a web shell to the web server.