PT-2026-49174 · Unknown · Huly Platform

·

CVE-2026-12212

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huly Platform versions prior to 0.7.1
Description Improper access controls in the RPC Interface component allow for remote attacks. The issue is located in the getMailboxSecret() function within the server/account/src/operations.ts file.
Recommendations Update to a version later than 0.7.0. As a temporary workaround, restrict access to the getMailboxSecret() function.

Fix

Incorrect Privilege Assignment

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12212

Affected Products

Huly Platform