CVE-2026-15721: Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources
Published Aug 4, 2026
·Updated
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Affected Software
1 affected component
HUMANIST Digital Human Resources>26.0<26.1
Event History
Aug 4, 2026
CVE Published
via MITRE·08:18 AM
Data Sourced
via MITRE·08:18 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15721?
The severity of CVE-2026-15721 is critical with a score of 9.8.
2
How do I fix CVE-2026-15721?
To fix CVE-2026-15721, upgrade HUMANIST Digital Human Resources to version 26.1 or later.
3
What type of vulnerability is CVE-2026-15721?
CVE-2026-15721 is an SQL Injection vulnerability.
4
What data is at risk with CVE-2026-15721?
CVE-2026-15721 can lead to the disclosure of sensitive data stored in cleartext.
5
Which versions of HUMANIST Digital Human Resources are affected by CVE-2026-15721?
CVE-2026-15721 affects HUMANIST Digital Human Resources versions prior to 26.1.