CVE-2026-14465: Session Fixation in Bilin Software's HUMANIST Digital Human Resources
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay).
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bilin Software HUMANIST Digital Human Resourcesto a version that resolves this vulnerability.Fixed in 26.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14465?
The severity of CVE-2026-14465 is medium with a CVSS score of 6.5.
How do I fix CVE-2026-14465?
To fix CVE-2026-14465, update HUMANIST Digital Human Resources to version 26.1 or later.
What is the impact of CVE-2026-14465?
CVE-2026-14465 allows session fixation attacks by enabling the reuse of session IDs, which could allow unauthorized access.
Which versions are affected by CVE-2026-14465?
CVE-2026-14465 affects the HUMANIST Digital Human Resources software versions before 26.1.
What type of vulnerability is CVE-2026-14465?
CVE-2026-14465 is classified as an insufficient session expiration vulnerability.