PT-2026-50521 · Hermes Webui · Hermes-Webui

Published

2026-06-17

·

Updated

2026-06-17

·

CVE-2026-55196

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.409
Description An authentication bypass exists in passkey registration endpoints. When HERMES WEBUI PASSKEY=1 is enabled and no credentials exist, unauthenticated remote attackers can register arbitrary passkeys. This occurs because the endpoints 'POST /api/auth/passkey/register/options' and 'POST /api/auth/passkey/register' are accessible without authentication, potentially allowing an attacker to claim the first passkey and obtain permanent administrative control.
Recommendations Update to version 0.51.409 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55196

Affected Products

Hermes-Webui