Junglewise Threat Intelligence

CVE-2026-55198: nesquena Hermes WebUI authorization bypass in session export endpoint

CVE-2026-55198 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Technologies: Nesquena Hermes WebUI. Vendors: Nesquena.

Executive brief

Hermes WebUI, a tool for managing and viewing session data, contains a security flaw in its session export feature. An authorized user could potentially access and download session transcripts belonging to other user profiles if they know or can guess the specific session ID. This could lead to the unauthorized exposure of sensitive conversation content and metadata from different organizational profiles.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `_handle_session_export` handler within `api/routes.py`. The endpoint fails to perform an ownership or profile-boundary check before serializing and streaming session data as JSON. An authenticated attacker with network access to the WebUI can exfiltrate session transcripts and metadata from foreign profiles by providing a target `session_id` to the `/api/session/export` endpoint. The vulnerability is addressed in version 0.51.443 by implementing the `_profiles_match` verification check before data serialization.

Affected products

  • nesquena hermes-webui < 0.51.443

Timeline

  • 2026-06-11: other: Fix proposed in pull request #3991
  • 2026-06-15: patched: Fix merged and released in version 0.51.443
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats