CVE-2026-55197 - Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint
CVE ID :CVE-2026-55197
Published : June 17, 2026, 5:59 p.m. | 3 hours, 39 minutes ago
Description :Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET /api/session?session_id=&messages=1 to retrieve unauthorized conversation transcripts and metadata.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 17, 2026, 5:59 p.m. | 3 hours, 39 minutes ago
Description :Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET /api/session?session_id=
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...