cbcvebase.
CVE-2026-55198
published 2026-06-17

CVE-2026-55198: Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint Hermes WebUI before 0.51.443 contains an authorization bypass…

high7.1CVSS 4.0
AVNACLATNPRLUINVCHVINVANSCNSINSAN
EPSS
0.27%
18.9th percentile
Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session data, enabling attackers to exfiltrate foreign session transcripts by guessing or knowing session identifiers.

Affected

1 ranges
VendorProductVersion rangeFixed in
nesquenahermes-webui< 0.51.4430.51.443
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.