CVE-2026-14465
Last modified
CVE-2026-14465 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | >= 26.0, < 26.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-14465?
How severe is CVE-2026-14465?
How do I fix CVE-2026-14465?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14456Issue summary: When an OpenSSL QUIC server (Listener SSL obj…7.5
- CVE-2026-14457Issue summary: In a server or client configuration with RFC7…7.5
- CVE-2026-14459Improper neutralization of argument delimiters in a command …8.8
- CVE-2026-1446There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS P…5
- CVE-2026-14460Missing Authorization vulnerability in TUBITAK BILGEM Softwa…8.8
- CVE-2026-14461mtr is vulnerable to Out-of-bound read vulnerability in ipin…5.1
- CVE-2026-14466It’s possible to run a stored XSS in Stormshield’s web admin…4.3
- CVE-2026-14468HashiCorp Terraform Enterprise contained an issue in its ver…7.7
- CVE-2026-1447The Mail Mint plugin for WordPress is vulnerable to Cross-Si…5.4
- CVE-2026-14470IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authent…6.5
- CVE-2026-14471Improper Neutralization of Special Elements in the metrics-s…8.6
- CVE-2026-14472The Kubio AI Page Builder plugin for WordPress is vulnerable…6.4
Are you affected by CVE-2026-14465?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
