← Back to search

CVE-2026-15721

9.8 CRITICAL

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources, which can lead to unauthorized access to sensitive data and potential data breaches.
Exploitability
Exploitation is relatively straightforward given the cleartext storage of sensitive information and the presence of SQL Injection, requiring only basic SQL knowledge and access to the affected system.
Blast radius
If exploited, this vulnerability could result in significant data breaches, compromising sensitive employee information and potentially leading to legal and reputational damage.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 26.1 or later.
sql-injectioncleartext-storagedata-breachweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-312

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.