CVE-2026-12060
Deferred Deferred - Pending Action

Heptabase Exposed Dangerous Method Allows Unauthorized Camera Access

Vulnerability report for CVE-2026-12060, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-12

Last updated on: 2026-06-12

Assigner: TWCERT/CC

Description

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-12
Last Modified
2026-06-12
Generated
2026-07-02
AI Q&A
2026-06-12
EPSS Evaluated
2026-07-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hepta_platforms heptabase to 1.90.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12060 is a vulnerability in the Heptabase application developed by Hepta Platforms. It is classified as an Exposed Dangerous Method or Function flaw. This vulnerability allows unauthenticated remote attackers to use social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application.

By doing so, the attacker can gain unauthorized access to the victim's camera and microphone permissions.

Impact Analysis

This vulnerability can impact you by allowing an attacker to remotely gain unauthorized access to your camera and microphone through the Heptabase application.

Such access could lead to privacy violations, as attackers could potentially spy on you or record audio and video without your consent.

Mitigation Strategies

The recommended immediate step to mitigate this vulnerability is to update the Heptabase application to version 1.90.2 or later.

Compliance Impact

This vulnerability allows unauthenticated remote attackers to gain unauthorized access to camera and microphone permissions by tricking victims into loading malicious webpages within the Heptabase application.

Unauthorized access to camera and microphone data can lead to privacy violations, which may impact compliance with data protection regulations such as GDPR and HIPAA that require safeguarding personal and sensitive information.

However, the provided information does not explicitly describe the direct effects on compliance with these standards or any regulatory consequences.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12060. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart