CVE-2026-58122Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-10: 3Patch / Workaround · 2026-07-10: 3Technical Details · 2026-07-10: 307-10
Signal classification1 categories
Patch
3100.0%
Full discourse3 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58122 — CVSS 9.1/10 █████████░ Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/9QMfnFicJD

    Post summary

    The tweet alerts about a critical authentication bypass in Hermes WebUI with a CVSS of 9.1, urges immediate patching, and does not provide a PoC or exploit details.

    1000084
    65 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Hermes WebUI Unauthenticated RCE via Terminal API (CVE-2026-58123) Hermes WebUI exposes its embedded terminal API endpoints with no authentication. A remote unauthenticated attacker can, in four sequential HTTP requests, create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint - achieving full shell command execution as the server process user. This is a direct, high-reliability unauth RCE: a browser-based shell reachable over HTTP without credentials. It's the second critical Hermes WebUI flaw from this cycle alongside the X-Forwarded-For auth bypass (CVE-2026-58122). 👉Upgrade Hermes WebUI to 0.51.788.

    Post summary

    Hermes WebUI has a critical unauthenticated RCE via its terminal API; upgrading to version 0.51.788 is the advised fix.

    00000116
    246 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Hermes WebUI Auth Bypass via X-Forwarded-For Spoofing (CVE-2026-58122) Hermes WebUI restricts its onboarding endpoints to local-origin IPs, but the check trusts the client-supplied X-Forwarded-For header. A remote unauthenticated attacker can send a spoofed X-Forwarded-For with a loopback address (127.0.0.1) to appear local and bypass the restriction. With that bypass, an attacker can perform SSRF against internal services and cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or start OAuth device-code flows to grab persistent access tokens stored in auth.json. 👉Upgrade Hermes WebUI to 0.51.307.

    Post summary

    The advisory discloses an X‑Forwarded‑For spoofing flaw in Hermes WebUI (CVE‑2026‑58122) that permits SSRF, configuration tampering, and token theft, and recommends upgrading to version 0.51.307 for remediation.

    00000127
    246 followersView on X

Explore more