PT-2026-50521 · Hermes Webui · Hermes-Webui
Published
2026-06-17
·
Updated
2026-06-17
·
CVE-2026-55196
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.409
Description
An authentication bypass exists in passkey registration endpoints. When
HERMES WEBUI PASSKEY=1 is enabled and no credentials exist, unauthenticated remote attackers can register arbitrary passkeys. This occurs because the endpoints 'POST /api/auth/passkey/register/options' and 'POST /api/auth/passkey/register' are accessible without authentication, potentially allowing an attacker to claim the first passkey and obtain permanent administrative control.Recommendations
Update to version 0.51.409 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui