PT-2026-50520 · Unknown · Hermes-Webui

CVE-2026-53871

·

Published

2026-06-17

·

Updated

2026-07-12

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.368
Description An authorization bypass exists in the get profile cookie() function, which accepts unauthenticated profile names from the hermes profile cookie. An authenticated attacker can forge the value of the hermes profile cookie to bypass profile-scoped authorization checks, allowing unauthorized access to sessions, files, and resources across different profiles.
Recommendations Update to version 0.51.368 or later. As a temporary workaround, restrict or monitor the use of the hermes profile cookie to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53871

Affected Products

Hermes-Webui