CVE-2026-12060 PUBLISHED

Hepta Platforms|Heptabase - Exposed Dangerous

Assigner: twcert
Reserved: 12.06.2026 Published: 12.06.2026 Updated: 12.06.2026

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Hepta Platforms
Product Heptabase
Versions Default: unaffected
  • affected from 0 to 1.90.2 (excl.)

Solutions

Please update to version 1.90.2 or later.

References

Problem Types

  • CWE-749 Exposed dangerous method or function CWE