Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-58123: Hermes WebUI < 0.51.788: Unauthenticated Remote Code Execution via Terminal API
CVE-2026-58123
CVE-2026-58123
Summary
A security flaw in older versions of Hermes WebUI allows attackers to run commands on the server without a password. This can happen if a hacker sends four specific requests to the server. To fix this, update to version 0.51.788 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| nesquena | hermes-webui | < 0.51.788 |
Original title
Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API
Original description
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process user via four sequential unauthenticated HTTP requests.
mitre CVSS3.1
9.8
Vulnerability type
CWE-306
Missing Authentication for Critical Function
- https://github.com/nesquena/hermes-webui/releases/tag/v0.51.788 release-notes
- https://github.com/nesquena/hermes-webui/pull/5268 issue-tracking
- https://github.com/nesquena/hermes-webui/commit/d257e5f36cfa9328600c8bde6f0de09a... patch
- https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-rce-via-termin... third-party-advisory
Published: 9 Jul 2026 · Updated: 20 Jul 2026 · First seen: 9 Jul 2026