What is CVE-2026-14175?
CVE-2026-14175: This vulnerability in Bilin Software's HUMANIST Digital Human Resources system allows unrestricted file upload with dangerous types, enabling attackers to upload a web shell using file upload mechanisms. It affects versions from 26.0 before 26.1; users should urgently upgrade to version 26.1.
Azərbaycanca: CVE-2026-14175: Bu zəiflik Bilin Software-in HUMANIST Digital Human Resources platformasında fayl yükləmə limitinin olmaması ilə bağlıdır və təhlükəli fayl tiplərinin (məsələn, web shell) serverə yüklənməsinə imkan verir. 26.0-dan 26.1 versiyasına qədər təsir edir; dərhal 26.1 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which Bilin Software product is affected by CVE-2026-14175?
This vulnerability affects Bilin Software's HUMANIST Digital Human Resources platform.
What security measure is recommended for CVE-2026-14175?
Users affected by versions from 26.0 before 26.1 are urged to urgently upgrade to version 26.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.