Broken Access Control Vulnerability in Hermes WebUI by Nesquena
CVE-2026-55197
7.1HIGH
What is CVE-2026-55197?
Hermes WebUI versions prior to 0.51.443 are susceptible to a vulnerability that allows authenticated users to exploit the /api/session endpoint. This flaw enables attackers to bypass profile boundary checks, granting them the ability to directly query for session IDs belonging to other profiles. As a result, unauthorized users can retrieve sensitive conversation transcripts and associated metadata, posing risks to user privacy and data security.
Affected Version(s)
hermes-webui 0 < 0.51.443
hermes-webui 0.51.443
