{"id":"CVE-2026-14804","published":"2026-08-04T10:19:32.417","lastModified":"2026-08-04T13:17:35.893","description":"Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves hard-coded cryptographic keys in HUMANIST Digital Human Resources, allowing sensitive constants to be read from an executable. This can lead to unauthorized access to sensitive information.","exploitability":"Exploitation is relatively straightforward given the hard-coded keys, requiring only access to the executable file.","blast_radius":"If exploited, this could result in unauthorized access to sensitive HR data, impacting confidentiality and potentially leading to data breaches.","remediation":"Upgrade to version 26.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["crypto","hardcoded","hr","sensitive"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:12:03.690Z"}}