Executive brief
Hermes WebUI, a web-based management interface, contains a security flaw in how it handles initial setup when passkeys are enabled. If the software is deployed to a publicly accessible server before the owner completes the initial configuration, an unauthorized person can register their own passkey first. This allows an attacker to claim administrative ownership of the system, potentially leading to full control over the application and its data.
Technical details
A missing authentication check (CWE-306) exists in the passkey registration endpoints of Hermes WebUI. When the environment variable HERMES_WEBUI_PASSKEY=1 is enabled and no credentials have been previously established, the POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication. An unauthenticated remote attacker can exploit this window of opportunity during the 'first-run' state to register the initial passkey, effectively bootstrapping themselves as the administrator. The fix, introduced in version 0.51.409 (and refined in 0.51.442), implements an onboarding gate that restricts initial registration to loopback or private network requests unless explicitly overridden by the operator.
Affected products
- nesquena Hermes WebUI before 0.51.409
Timeline
- 2026-06-14: other: Initial fix proposed in pull request #4171
- 2026-06-15: patched: Fix merged and released in version 0.51.442
- 2026-06-17: disclosed: CVE-2026-55196 published
References
- https://github.com/nesquena/hermes-webui/commit/4d90577e25d5537cb07290eca3fb8abff3bab316
- https://github.com/nesquena/hermes-webui/pull/4171
- https://github.com/nesquena/hermes-webui/pull/4267
- https://github.com/nesquena/hermes-webui/releases/tag/v0.51.442
- https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-passkey-registration-via-authentication-bypass