Path Traversal Vulnerability in Hermes WebUI Affects Sensitive Data Security
CVE-2026-11322

7.1HIGH

Key Information:

Vendor

Nesquena

Vendor
CVE Published:
4 June 2026

What is CVE-2026-11322?

Hermes WebUI versions prior to v0.51.221 are susceptible to a path traversal vulnerability stemming from improper handling of symbolic links. This flaw permits attackers to access files and directories beyond the intended workspace root by exploiting the file and listing APIs. As a result, attackers may gain unauthorized access to sensitive data stored on the server, including SSH keys, cloud credentials, and application tokens, thereby compromising the security of the affected systems.

Affected Version(s)

Hermes WebUI 0 < 0.51.221

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.