PT-2026-48730 · Unknown · Hermes-Webui

CVE-2026-49973

·

Published

2026-06-11

·

Updated

2026-06-13

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.358
Description Improper access control allows unauthenticated remote attackers to hijack the initial setup process. By sending a POST request to the settings API endpoint without network origin restrictions, an attacker can submit the set password parameter to persist an arbitrary password hash. This action enables the attacker to obtain a valid session cookie and lock the legitimate operator out of the instance.
Recommendations Update to version 0.51.358 or later. Isolate affected systems immediately to prevent unauthorized access.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49973

Affected Products

Hermes-Webui