CVE-2026-14194: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal.
This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-14194
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-141940.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14194 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Improper Limitation of
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-47613: NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitati…nvd · 2026-08-04
- highCVE-2026-47612: NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attac…nvd · 2026-08-04
- highCVE-2026-61372: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability i…nvd · 2026-08-03
- highCVE-2026-12733: IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improp…nvd · 2026-07-30
- unknownCVE-2026-44943: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit…nvd · 2026-07-29
- highCVE-2026-48374: Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Tr…nvd · 2026-07-28
More from NVD Recent CVEs
- highCVE-2026-7529: The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unau…2026-08-05
- mediumCVE-2026-7456: The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to …2026-08-05
- highCVE-2026-67623: Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attacker…2026-08-05
- highCVE-2026-17506: The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi…2026-08-05
- highCVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-services component,…2026-08-05