CVE-2026-14194: Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human Resources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bilin Software and Informatics Consultancy Inc HUMANI ST Digital Human Resourcesto a version that resolves this vulnerability.Fixed in 26.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14194?
CVE-2026-14194 has a medium severity rating of 6.5.
What type of vulnerability is CVE-2026-14194?
CVE-2026-14194 is classified as a Path Traversal vulnerability.
How does CVE-2026-14194 affect HUMANIST Digital Human Resources?
CVE-2026-14194 allows for arbitrary file downloads due to improper path limitations.
What versions of HUMANIST Digital Human Resources are affected by CVE-2026-14194?
CVE-2026-14194 affects HUMANIST Digital Human Resources versions prior to 26.1.
How can I mitigate CVE-2026-14194?
To mitigate CVE-2026-14194, upgrade to HUMANIST Digital Human Resources version 26.1 or later.