PT-2026-47854 · Nesquena · Hermes-Webui

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-49956

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Attackers can send requests to the sessions search handler to retrieve session titles and transcript message content from profiles other than their own active profile.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-49956

Affected Products

Hermes-Webui