CVE-2026-18993
Deferred Deferred - Pending Action

Improper Access Control in NousResearch Hermes-Agent Memory Toolset

Vulnerability report for CVE-2026-18993, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-12

Assigner: VulDB

Description

A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-12
Generated
2026-08-17
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-16
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nousresearch hermes-agent to 0.16.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A vulnerability exists in NousResearch hermes-agent versions up to 0.16.0, specifically in the file hermes-agent/model_tools.py under the Memory Toolset component. This flaw allows improper access controls, potentially enabling unauthorized remote access to the system.

Detection Guidance

Check Hermes Agent versions up to 0.16.0 for unauthorized memory toolset access. Inspect agent_init.py for late-stage tool injection logic ignoring disabled_toolsets. Verify if fact_store or fact_feedback tools appear in valid_tool_names despite being disabled.

Impact Analysis

The vulnerability may allow attackers to remotely exploit improper access controls, potentially leading to unauthorized access, data manipulation, or other malicious activities depending on the system's configuration and permissions.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by enabling unauthorized access to memory tools that may handle sensitive data. Improper access controls could lead to unauthorized persistence or modification of sensitive information, violating data protection requirements under these regulations.

Mitigation Strategies

Update NousResearch hermes-agent to version 0.16.0 or later to address the improper access controls issue. If immediate update is not possible, restrict network access to the vulnerable component hermes-agent/model_tools.py and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18993. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart