🔐 CVE Alert

CVE-2026-12060

MEDIUM 6.5

Hepta Platforms|Heptabase - Exposed Dangerous

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.

CWE CWE-749
Vendor hepta platforms
Product heptabase
Published Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for hepta platforms heptabase

Be the first to know when new medium vulnerabilities affecting hepta platforms heptabase are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Hepta Platforms / Heptabase
0 < 1.90.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
twcert.org.tw: https://www.twcert.org.tw/tw/cp-132-10968-6be4c-1.html twcert.org.tw: https://www.twcert.org.tw/en/cp-139-10967-4947d-2.html