Improper Authorization in Huly Platform by hcengineering
CVE-2026-12213

5.3MEDIUM

Key Information:

Vendor
CVE Published:
15 June 2026

What is CVE-2026-12213?

A vulnerability exists in the Huly Platform, specifically in the getAccountInfo function within the User Information Handler component. This flaw allows for improper authorization, facilitating potential unauthorized access to user accounts. The vulnerability can be exploited remotely, making it particularly concerning for users of the platform. Despite early contact regarding this security issue, the vendor has not provided any response, leaving the exploitation risk unaddressed. It is crucial for users to review their security posture and apply necessary mitigations or updates.

Affected Version(s)

Huly Platform 0.1

Huly Platform 0.2

Huly Platform 0.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geochen (VulDB User)
VulDB CNA Team
.