Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.

Project Subscriptions

Vendors Products
Hepta Platforms Subscribe
Heptabase Subscribe
Advisories

No advisories yet.

Fixes

Solution

Please update to version 1.90.2 or later.


Workaround

No workaround given by the vendor.

History

Fri, 12 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hepta Platforms
Hepta Platforms heptabase
Vendors & Products Hepta Platforms
Hepta Platforms heptabase

Fri, 12 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Description Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.
Title Hepta Platforms|Heptabase - Exposed Dangerous
Weaknesses CWE-749
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-06-12T13:54:04.105Z

Reserved: 2026-06-12T06:01:43.245Z

Link: CVE-2026-12060

cve-icon Vulnrichment

Updated: 2026-06-12T13:53:58.161Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T07:16:21.090

Modified: 2026-06-12T16:00:18.860

Link: CVE-2026-12060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T20:21:00Z

Weaknesses