CVE-2026-12060: Hepta Platforms|Heptabase - Exposed Dangerous
Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Heptabaseto a version that resolves this vulnerability.Fixed in 1.90.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12060?
The severity of CVE-2026-12060 is medium with a CVSS score of 6.5.
How do I fix CVE-2026-12060?
To fix CVE-2026-12060, please update to version 1.90.2 or later of the Heptabase application.
What impact does CVE-2026-12060 have on Heptabase?
CVE-2026-12060 allows unauthenticated remote attackers to exploit a dangerous method or function through social engineering techniques.
Who is affected by CVE-2026-12060?
Users of Hepta Platforms Heptabase who do not update to the latest versions are affected by CVE-2026-12060.
What is the nature of the vulnerability in CVE-2026-12060?
CVE-2026-12060 is an exposed dangerous method or function vulnerability that could be exploited through malicious web pages.