CVE-2026-15721
9.8 CRITICALPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources, which can lead to unauthorized access to sensitive data and potential data breaches.
- Exploitability
- Exploitation is relatively straightforward given the cleartext storage of sensitive information and the presence of SQL Injection, requiring only basic SQL knowledge and access to the affected system.
- Blast radius
- If exploited, this vulnerability could result in significant data breaches, compromising sensitive employee information and potentially leading to legal and reputational damage.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 26.1 or later.
sql-injectioncleartext-storagedata-breachweb
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-312
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-72507PoC
- HIGHCVE-2026-78309
- HIGHCVE-2022-4997
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- CRITICALCVE-2026-12718
- CRITICALCVE-2026-15360
Related by shared AI tags and CWE weakness class. Browse the full archive.