{"id":"CVE-2026-14175","published":"2026-08-04T10:19:31.633","lastModified":"2026-08-04T14:16:30.147","description":"Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to upload a web shell, enabling remote code execution, due to the unrestricted file upload feature in HUMANIST Digital Human Resources versions before 26.1.","exploitability":"Exploitation is relatively straightforward as it requires no user interaction and can be automated. The attacker needs to upload a file with a dangerous type to the web server.","blast_radius":"If exploited, this vulnerability could lead to full control over the web server, potentially leading to data theft, service disruption, and further attacks on the network.","remediation":"Upgrade to HUMANIST Digital Human Resources 26.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","upload","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:03:10.996Z"}}