CVE-2026-53871

HIGH

Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie

Title source: cna
STIX 2.1

Description

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles.

Scores

CVSS v3 8.1
EPSS 0.0037
EPSS Percentile 28.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-565
Status published
Products (2)
nesquena/hermes-webui < 0.51.368
nesquena/hermes-webui 0.51.368
Published Jun 17, 2026
Tracked Since Jun 18, 2026