CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-58122

Critical · CVSS 9.1

Hermes WebUI — Authentication bypass via X-Forwarded-For header spoofing (IP origin restriction circumvention)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-348

Description

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.

Search profile — drives PoC discovery

Symbols X-Forwarded-Forauth.jsononboardingloopback127.0.0.1OAuth device-codeLLM provider configurationcloud metadatalocal-origin IP restrictionsnesquena/hermes-webui
Keywords CVE-2026-58122Hermes WebUI authentication bypassX-Forwarded-For spoofing loopbackhermes-webui onboarding bypassCWE-348 IP spoofing hermeshermes-webui SSRF metadatahermes-webui OAuth device-code exploithermes-webui auth.jsonhermes-webui LLM config overwritenesquena hermes-webui PoC
Versions: < 0.51.307

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z