CVE-2026-53871
Deferred Deferred - Pending Action
Authorization Bypass in Hermes WebUI via Cookie Forgery

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: VulnCheck

Description
Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-18
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hermes hermes_webui to 0.51.368 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-565 The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

Hermes WebUI before version 0.51.368 has an authorization bypass vulnerability in the get_profile_cookie() function. This function accepts unauthenticated profile names from the hermes_profile cookie. Because of this, an authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks.

This allows the attacker to access sessions, files, and resources across different profiles that they should not normally be able to access.

Impact Analysis

This vulnerability can allow an authenticated attacker to bypass authorization controls and gain unauthorized access to sessions, files, and resources belonging to other profiles.

Such unauthorized access can lead to data exposure, potential data manipulation, and compromise of sensitive information across different user profiles.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53871. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart