CVE-2026-55196

CRITICAL

Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass

Title source: cna
STIX 2.1

Description

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control.

References (5)

Core 5

Scores

CVSS v3 9.1
EPSS 0.0058
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-306
Status published
Products (2)
hermes-webui/hermes-webui < 0.51.409
hermes-webui/hermes-webui 0.51.409
Published Jun 17, 2026
Tracked Since Jun 18, 2026