CVE-2026-58123Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process user via four sequential unauthenticated HTTP requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-09); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Mentions · 2026-09-10: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-09-10: 107-0907-1009-10
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-091
Patch1
2026-07-101
Patch1
2026-09-101
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-58123 - critical 🚨 Hermes WebUI < 0.51.788 - Remote Code Execution > Hermes WebUI < 0.51.788 contains an unauthenticated remote code execution caused by i... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-58123 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-58123 is disclosed as an unauthenticated remote code execution vulnerability in Hermes WebUI versions below 0.51.788; no PoC, exploit, or patch information is included.

    01082535
    1.3K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58123 — CVSS 9.8/10 ██████████ Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/7s5UXvBpEj

    Post summary

    CVE-2026-58123 is a critical unauthenticated remote code execution vulnerability affecting Hermes WebUI before version 0.51.788; a patch is available and should be applied immediately.

    1001071
    64 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Hermes WebUI Unauthenticated RCE via Terminal API (CVE-2026-58123) Hermes WebUI exposes its embedded terminal API endpoints with no authentication. A remote unauthenticated attacker can, in four sequential HTTP requests, create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint - achieving full shell command execution as the server process user. This is a direct, high-reliability unauth RCE: a browser-based shell reachable over HTTP without credentials. It's the second critical Hermes WebUI flaw from this cycle alongside the X-Forwarded-For auth bypass (CVE-2026-58122). 👉Upgrade Hermes WebUI to 0.51.788.

    Post summary

    Hermes WebUI has an unauthenticated RCE via its terminal API (CVE‑2026‑58123). Users should upgrade to version 0.51.788 to mitigate this critical flaw.

    00000116
    246 followersView on X

Explore more