CVE-2026-6832Patch(get-hermes / hermes_web_ui)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch get-hermes hermes_web_ui systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSON files on the host system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hermes_web_ui

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
hermes_web_ui

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-26: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-26: 104-2204-26
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-261
Disclosure1
Full discourse2 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🧨 CVE-2026-6832 (High) — Another fresh High from Tenable’s 2026‑04‑21/22 updates. New CVEs at this level usually mix remote reachability with real impact. If your assets light up on this, pull it into your “internet‑facing first” patch queue. Source: https://www.tenable.com/cve/CVE-2026-6832

    Post summary

    A newly disclosed high‑severity vulnerability (CVE-2026-6832) is announced, with the main recommendation being to add affected assets to the patch queue.

    1003076
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6832 Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the sessi… https://www.cve.org/CVERecord?id=CVE-2026-6832

    Post summary

    The text provides a brief disclosure of CVE‑2026‑6832, highlighting an arbitrary file deletion flaw in Hermes WebUI’s /api/session/delete endpoint that permits authenticated attackers to delete files beyond expected boundaries.

    00000173
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appget-hermeshermes_web_ui---

Explore more