PT-2026-50520 · Unknown · Hermes-Webui
CVE-2026-53871
·
Published
2026-06-17
·
Updated
2026-07-12
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.368
Description
An authorization bypass exists in the
get profile cookie() function, which accepts unauthenticated profile names from the hermes profile cookie. An authenticated attacker can forge the value of the hermes profile cookie to bypass profile-scoped authorization checks, allowing unauthorized access to sessions, files, and resources across different profiles.Recommendations
Update to version 0.51.368 or later.
As a temporary workaround, restrict or monitor the use of the
hermes profile cookie to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui