/Vulnerability Library

Hermes WebUI < 0.51.788 - Remote Code Execution

CVE-2026-58123
Verified

Description

Hermes WebUI < 0.51.788 contains an unauthenticated remote code execution caused by improper access control in embedded terminal API endpoints, letting remote attackers execute arbitrary shell commands without credentials.

Severity

Critical

CVSS Score

9.8

Exploit Probability

5%

Affected Product

hermes-webui

Published Date

September 2, 2026

Template Author

str4k3r

CVE-2026-58123.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-58123
CWE ID:
cwe-306

References

https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-rce-via-terminal-apihttps://github.com/nesquena/hermes-webui/commit/d257e5f36cfa9328600c8bde6f0de09a6ad9b6f4https://github.com/nesquena/hermes-webui/releases/tag/v0.51.788https://nvd.nist.gov/vuln/detail/CVE-2026-58123

Remediation Steps

Update to version 0.51.788 or later.