← Back to search

CVE-2026-14175

9.8 CRITICAL

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
This vulnerability allows an attacker to upload a web shell, enabling remote code execution, due to the unrestricted file upload feature in HUMANIST Digital Human Resources versions before 26.1.
Exploitability
Exploitation is relatively straightforward as it requires no user interaction and can be automated. The attacker needs to upload a file with a dangerous type to the web server.
Blast radius
If exploited, this vulnerability could lead to full control over the web server, potentially leading to data theft, service disruption, and further attacks on the network.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to HUMANIST Digital Human Resources 26.1 or later.
rceuploadweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.