
CVE-2026-22677 Hermes WebUI prior to 0.51.44 - Release T contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary… https://www.cve.org/CVERecord?id=CVE-2026-22677
Post summary
The post announces a path‑traversal flaw in Hermes WebUI (prior to v0.51.44) that allows authenticated attackers to read arbitrary files, but it offers no PoC, exploit code, patch, or evidence of active exploitation.

