Junglewise Threat Intelligence

CVE-2026-53871: Nesquena Hermes WebUI authorization bypass in get_profile_cookie

CVE-2026-53871 · Severity: high · CVSS 8.1 · Published 2026-06-17

Technologies: Nesquena Hermes WebUI. Vendors: Nesquena.

Executive brief

Hermes WebUI, a web-based interface for managing data profiles and sessions, contains a security flaw in how it handles user profiles. An authenticated user can manipulate their browser cookies to trick the system into granting them access to data, files, and sessions belonging to other profiles. This could lead to unauthorized access to sensitive information or the ability to modify data across different workspaces or tenants.

Technical details

An authorization bypass exists in the `get_profile_cookie()` function within Hermes WebUI. The application relies on the `hermes_profile` cookie to determine the active profile context for profile-scoped routes and visibility guards. Because this cookie was not cryptographically bound to the user's session or authenticated on the server side, an attacker with valid credentials can manually modify the cookie value to any target profile name. This allows the attacker to bypass profile-scoped authorization checks and perform cross-profile operations on sessions, files, and resources. The fix, introduced in version 0.51.368, implements HMAC-signing of the profile cookie bound to the session token.

Affected products

  • nesquena Hermes WebUI < 0.51.368

Timeline

  • 2026-06-12: patched: Fix merged in version 0.51.368
  • 2026-06-17: disclosed: CVE published to NVD

References