PatchSiren cyber security CVE debrief
CVE-2026-55197 nesquena CVE debrief
CVE-2026-55197 debrief based on the supplied source corpus. The CVE record was published on 2026-06-17T19:18:13.340Z and has not been modified since then. The vulnerability affects Hermes WebUI before version 0.51.443, allowing authenticated users to disclose cross-profile session transcripts via the /api/session endpoint. This broken access control vulnerability enables attackers to bypass profile boundary checks by directly querying session IDs belonging to other profiles. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity.
- Vendor
- nesquena
- Product
- hermes-webui
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-09-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-09-17
Who should care
Defenders responsible for Hermes WebUI deployments should assess exposure and prioritize remediation to prevent unauthorized session transcript disclosure. This includes verifying the version of Hermes WebUI and restricting access to the /api/session endpoint. Additionally, defenders should review official advisories and monitor for suspicious activity related to session transcript disclosure.
Why it matters
CVE-2026-55197 is a high-severity vulnerability in Hermes WebUI that allows authenticated users to disclose cross-profile session transcripts. Defenders should prioritize verifying exposure and remediating vulnerable instances to prevent unauthorized access to sensitive information.
- Potential disclosure of unauthorized conversation transcripts and metadata.
- Possible bypass of profile boundary checks.
- Required verification of Hermes WebUI instances for exposure to unauthorized session transcript disclosure.
- Need for restricted access to the /api/session endpoint.
Technical summary
The /api/session endpoint in Hermes WebUI before 0.51.443 contains a broken access control vulnerability that allows authenticated users to disclose cross-profile session transcripts by directly querying session IDs belonging to other profiles. This vulnerability enables attackers to bypass profile boundary checks and retrieve unauthorized conversation transcripts and metadata. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Defenders should prioritize verifying exposure and remediating vulnerable instances to prevent unauthorized access to sensitive information.
Defensive priority
Defenders should prioritize verifying exposure of Hermes WebUI instances to unauthorized session transcript disclosure via the /api/session endpoint.
Recommended defensive actions
- Verify Hermes WebUI instances for exposure to unauthorized session transcript disclosure via the /api/session endpoint.
- Restrict access to the /api/session endpoint to prevent unauthorized session ID queries.
- Upgrade Hermes WebUI to version 0.51.443 or later to address the broken access control vulnerability.
- Monitor for suspicious activity related to session transcript disclosure.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the broken access control vulnerability in Hermes WebUI before 0.51.443, allowing authenticated users to disclose cross-profile session transcripts. Evidence is limited to public CVE and NVD sources. Defenders should verify exposure and review official advisories for additional details. The vulnerability is confirmed to exist in versions prior to 0.51.443, but specific exploit details are not provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55197 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55197
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55197 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55197
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nesquena/hermes-webui/commit/2a3baa71b81ca92da8ece8616a09f15894beec71
-
Source reference
Unverified legacy reference
URL: https://github.com/nesquena/hermes-webui/pull/3982
-
Source reference
Unverified legacy reference
URL: https://github.com/nesquena/hermes-webui/pull/4269
-
Source reference
Unverified legacy reference
URL: https://github.com/nesquena/hermes-webui/releases/tag/v0.51.443
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/hermes-webui-broken-access-control-in-api-session-endpoint
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.