What is CVE-2026-14838?
This vulnerability in Bilin Software's HUMANIST Digital Human Resources arises from the use of the GET request method with sensitive query strings, leading to potential session hijacking. It affects versions starting from 26.0 to before 26.1. Affected systems should be immediately upgraded to version 26.1 or later.
Azərbaycanca: Bu zəiflik Bilin Software-in HUMANIST Digital Human Resources sistemində GET sorğu metodunun həssas məlumatlar (məsələn, sessiya tokenləri) ilə istifadəsinə görə yaranır. Problem proqramın 26.0-dan 26.1-ə qədərki versiyalarına təsir edir və uğurlu istismar sessiya oğurluğuna (Session Hijacking) səbəb ola bilər. Təsirlənmiş sistemləri dərhal 26.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Bilin Software and Informatics Consultancy Inc.
FAQ2
Which Bilin Software product is affected by CVE-2026-14838?
This vulnerability affects Bilin Software's HUMANIST Digital Human Resources.
What is the primary risk if CVE-2026-14838 is successfully exploited?
Successful exploitation can lead to session hijacking.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.