Profile Isolation Bypass in Hermes WebUI by Nesquena
CVE-2026-49956
7.1HIGH
What is CVE-2026-49956?
Hermes WebUI versions prior to 0.51.269 are vulnerable to a profile isolation bypass issue that allows authenticated users to access data from other user profiles. By querying the session search endpoint without proper active-profile filtering in place, attackers can retrieve sensitive information including session titles and message transcripts from profiles other than their own. This flaw poses a significant risk to user data confidentiality and illustrates the critical need for implementing robust access controls.
Affected Version(s)
hermes-webui 0
