PT-2026-64787 · Nousresearch · Hermes-Agent

·

CVE-2026-17432

·

Published

2026-07-26

·

Updated

2026-07-27

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions NousResearch hermes-agent version 2026.6.5
Description Improper access controls exist within the SimpleX Gateway Authorization component, specifically in the file hermes-agent/plugins/platforms/simplex/adapter.py. A remote attacker can exploit this by manipulating the contactId argument. This attack is characterized by high complexity and is considered difficult to execute.
Recommendations Apply patch 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3 for version 2026.6.5.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17432

Affected Products

Hermes-Agent