CVE-2026-49973
Published: Thu, 11 Jun 2026 20:16
Summary
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to
Details
Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an arbitrary password hash, obtain a valid session cookie, and lock out the legitimate operator from their own instance.
Are YOU affected by CVE-2026-49973?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2026-49973 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://github.com/nesquena/hermes-webui/commit/1126e541325d401538f6a272a9c024c37d47ae08
- https://github.com/nesquena/hermes-webui/pull/3964
- https://github.com/nesquena/hermes-webui/pull/3973
- https://github.com/nesquena/hermes-webui/releases/tag/v0.51.358
- https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-password-takeover-via-api-settings
- https://github.com/nesquena/hermes-webui/pull/3964
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.