Junglewise Threat Intelligence

CVE-2026-58122: nesquena Hermes WebUI authentication bypass in onboarding endpoints

CVE-2026-58122 · Severity: critical · CVSS 9.1 · Published 2026-07-09

Technologies: Nesquena Hermes WebUI. Vendors: Nesquena.

Executive brief

Hermes WebUI, a management interface for Large Language Model (LLM) services, contains a security flaw in its initial setup process. An attacker can trick the system into thinking they are accessing it from the local server by spoofing network headers. This allows them to bypass security checks to steal sensitive API keys, modify AI provider settings, or gain permanent access to the system.

Technical details

An authentication bypass vulnerability exists in the onboarding gate of Hermes WebUI due to improper validation of the X-Forwarded-For and X-Real-IP HTTP headers. By supplying a loopback address (e.g., 127.0.0.1) in these headers, a remote unauthenticated attacker can bypass IP-based restrictions intended to limit onboarding access to local users. Successful exploitation allows the attacker to perform Server-Side Request Forgery (SSRF) against internal metadata endpoints, overwrite LLM provider configurations and API keys, or initiate OAuth device-code flows to obtain persistent access tokens. The issue is fixed in version 0.51.307 by ignoring forwarded headers for locality checks unless explicitly configured via the HERMES_WEBUI_TRUST_FORWARDED_FOR environment variable.

Affected products

  • nesquena Hermes WebUI < 0.51.307

Timeline

  • 2026-06-06: patched: Fix committed in version 0.51.307
  • 2026-07-09: disclosed: CVE published and NVD record created

References