Executive brief
Hermes WebUI, a web-based management interface, contains a security flaw in its initial setup process. When the software is first installed and has no password configured, an unauthorized person on the network can remotely set their own password before the legitimate owner does. This allows an attacker to take full control of the interface and lock out the intended administrator.
Technical details
An improper access control vulnerability exists in the `POST /api/settings` endpoint of Hermes WebUI. When the application is in its initial "no-password" state, the settings API remains reachable without authentication to facilitate setup. However, the endpoint failed to restrict the `_set_password` parameter to local or private network origins. An unauthenticated remote attacker can submit a password hash to this endpoint, which persists the new credentials, establishes ownership, and issues a valid session cookie to the attacker. This effectively locks out the legitimate administrator. The vulnerability is resolved in version 0.51.358 by gating first-run password bootstrap to loopback/private networks unless explicitly overridden by the `HERMES_WEBUI_ONBOARDING_OPEN` environment variable.
Affected products
- nesquena Hermes WebUI < 0.51.358
Timeline
- 2026-06-10: patched: Fix committed to repository
- 2026-06-11: advisory: NVD and vendor advisory published
References
- https://github.com/nesquena/hermes-webui/commit/1126e541325d401538f6a272a9c024c37d47ae08
- https://github.com/nesquena/hermes-webui/pull/3964
- https://github.com/nesquena/hermes-webui/pull/3973
- https://github.com/nesquena/hermes-webui/releases/tag/v0.51.358
- https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-password-takeover-via-api-settings