Authentication Bypass in Hermes WebUI Affects User Control
CVE-2026-55196
9.1CRITICAL
What is CVE-2026-55196?
The Hermes WebUI prior to version 0.51.409 has a serious security flaw that allows remote attackers to bypass authentication mechanisms. Specifically, when the passkey registration feature is enabled without existing credentials, attackers can access unprotected endpoints. As a result, they can register arbitrary passkeys through the POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints, granting them undue administrative control over the system. This vulnerability poses a significant risk to users, as it allows attackers to seize control without needing any prior authentication.
Affected Version(s)
hermes-webui 0 < 0.51.409
hermes-webui 0.51.409
