Junglewise Threat Intelligence

CVE-2026-12213: hcengineering Huly Platform improper authorization in getAccountInfo

CVE-2026-12213 · Severity: medium · CVSS 4.3 · Published 2026-06-15

Technologies: Hcengineering Huly Platform. Vendors: Hcengineering.

Executive brief

The Huly Platform, an open-source process management and collaboration tool, contains a security flaw in how it handles user account information. An authenticated user can exploit this vulnerability to access account details they are not authorized to see. This could lead to the exposure of sensitive user data and potentially impact the privacy of individuals within the organization.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in the Huly Platform up to version 0.7.0. The flaw is located in the 'getAccountInfo' function within 'server/account/src/operations.ts' of the User Information Handler component. A remote attacker with low-level privileges can exploit this by manipulating requests to bypass authorization checks and retrieve account information belonging to other users. While the attack requires authentication, it can be executed over the network without user interaction. A public exploit is reportedly available, and as of the advisory date, no official patch has been confirmed by the vendor.

Affected products

  • hcengineering Huly Platform up to 0.7.0

Timeline

  • 2026-06-15: disclosed: Vulnerability disclosed via VulDB and NVD
  • 2026-06-15: advisory: CVE-2026-12213 published

References

Related threats