PT-2026-48730 · Unknown · Hermes-Webui
CVE-2026-49973
·
Published
2026-06-11
·
Updated
2026-06-13
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.358
Description
Improper access control allows unauthenticated remote attackers to hijack the initial setup process. By sending a POST request to the settings API endpoint without network origin restrictions, an attacker can submit the
set password parameter to persist an arbitrary password hash. This action enables the attacker to obtain a valid session cookie and lock the legitimate operator out of the instance.Recommendations
Update to version 0.51.358 or later.
Isolate affected systems immediately to prevent unauthorized access.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui