Improper Access Control Vulnerability in Huly Platform by HC Engineering
CVE-2026-12212

5.3MEDIUM

Key Information:

Vendor
CVE Published:
15 June 2026

What is CVE-2026-12212?

A vulnerability in the Huly Platform from HC Engineering affects versions up to 0.7.0, specifically in the function getMailboxSecret within the RPC Interface component. This vulnerability allows for improper access control, which can be exploited remotely. The attack vector exposes users to potential unauthorized access, compromising sensitive information. The vendor was notified about the issue prior to public disclosure but did not respond, increasing concerns over unaddressed security ramifications.

Affected Version(s)

Huly Platform 0.1

Huly Platform 0.2

Huly Platform 0.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geochen (VulDB User)
VulDB CNA Team
.