Home

Description

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles.

PUBLISHED Reserved 2026-06-10 | Published 2026-06-17 | Updated 2026-06-17 | Assigner VulnCheck




HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

Reliance on Cookies without Validation and Integrity Checking

Product status

Default status
unaffected

Any version before 0.51.368
affected

0.51.368 (semver)
unaffected

Credits

Chia Min Jun Lennon finder

References

github.com/nesquena/hermes-webui/releases/tag/v0.51.368 (Release Notes) release-notes

github.com/nesquena/hermes-webui/pull/4023 (Researcher Pull Request) technical-description

github.com/nesquena/hermes-webui/pull/4036 (Maintainer Pull Request) issue-tracking

github.com/...ommit/9e96f5f6adf93b6d1e27ebddfb4d2833ca06ff3b patch

www.vulncheck.com/...bypass-via-forged-hermes-profile-cookie third-party-advisory

cve.org (CVE-2026-53871)

nvd.nist.gov (CVE-2026-53871)

Download JSON