Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14838 exploits a fundamental web security flaw where HUMANIST Digital Human Resources transmits sensitive authentication data through GET request query strings instead of secure POST methods. This vulnerability affects versions 26.0 through 26.1 and creates a direct pathway for session hijacking attacks. Organizations using this HR platform are at risk because query parameters are logged in browser history, server logs, proxies, and network traffic—making session tokens and credentials visible to anyone with access to these records. The attack surface is particularly dangerous in enterprise environments where multiple systems and users have visibility into HTTP request logs.
While MITRE ATT&CK mappings aren't formally assigned to this CVE, practitioners using Casky.ai would detect attack patterns aligned with credential access and lateral movement techniques. Claude's extended reasoning capabilities enable detection of suspicious query string patterns containing session identifiers, authentication tokens, and user credentials—signatures of CWE-598 exploitation. Security teams would observe findings showing anomalous GET requests with sensitive parameters being replayed from unusual locations or IP addresses, cleartext credential exposure in proxy logs, and unauthorized session activity originating from different geographic regions. Though zero Casky skills currently map to this specific vulnerability, the platform's continuous skill expansion and Claude's reasoning engine can help teams recognize when attackers are leveraging exposed session data for unauthorized HR system access and data exfiltration.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14838. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation