CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-49973

Critical · CVSS 9.4

Hermes WebUI — Improper Access Control / Missing Authentication for Critical Function (CWE-306) - Unauthenticated Initial Setup Hijack

CVSS
9.4
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-306

Description

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an arbitrary password hash, obtain a valid session cookie, and lock out the legitimate operator from their own instance.

Search profile — drives PoC discovery

Symbols _set_passwordsettings/api/settingsfirst-runsession cookiepassword hashPOST /settings
Keywords CVE-2026-49973Hermes WebUI unauthenticatedhermes-webui _set_passwordhermes-webui settings API takeoverhermes-webui first-run hijackhermes-webui CWE-306nesquena hermes-webui exploithermes-webui password hijack PoChermes-webui setup bypass
Versions: < 0.51.358

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z