Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14804 is a critical vulnerability (CVSS 9.1) affecting HUMANIST Digital Human Resources versions 26.0 through 26.0.x, stemming from hard-coded cryptographic keys embedded directly in the application executable. This CWE-321 weakness allows attackers to extract sensitive constants from compiled binaries, potentially compromising encryption mechanisms that protect HR data—including employee records, compensation information, and authentication credentials. Organizations using affected versions face immediate risk of data exfiltration, as attackers can reverse-engineer the application to recover cryptographic material and decrypt sensitive communications or stored data.
While this CVE currently lacks MITRE ATT&CK technique mapping, Casky's AI-driven analysis identifies the core attack patterns associated with hard-coded credentials: initial reconnaissance through binary analysis (Discovery techniques), credential dumping from executables, and lateral movement enabled by compromised cryptographic material. Although no specific Casky skills directly map to this vulnerability at present, practitioners should use the platform to hunt for related weaknesses in their environment—querying for insecure credential storage patterns, unencrypted sensitive data at rest, and privilege escalation vectors that leverage recovered keys. Security teams should immediately audit HUMANIST deployments, extract and rotate all hard-coded keys, and implement secrets management solutions to prevent similar vulnerabilities in future releases.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14804. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation