Junglewise Threat Intelligence

CVE-2026-58123: nesquena Hermes WebUI unauthenticated RCE in terminal API

CVE-2026-58123 · Severity: critical · CVSS 9.8 · Published 2026-07-09

Technologies: Nesquena Hermes WebUI. Vendors: Nesquena.

Executive brief

Hermes WebUI, a management interface for workspace environments, contains a critical flaw in its embedded terminal feature. When the software is used without a password (the default configuration) and exposed to a network, an attacker can gain full control over the server by sending a series of web requests. This allows unauthorized individuals to execute arbitrary commands, potentially leading to complete data theft or system takeover.

Technical details

A missing authentication check (CWE-306) in the embedded terminal API of Hermes WebUI allows unauthenticated remote code execution. The vulnerability exists because the 'check_auth()' function returns True by default when no password or passkey is configured, leaving the terminal endpoints (/api/terminal/start, /api/terminal/input, etc.) accessible to any network caller. An attacker can achieve full command execution as the server process user by making four sequential HTTP requests to initialize a session, attach a PTY shell, and input arbitrary shell commands. The issue is addressed in version 0.51.788 by implementing a local-origin gate that restricts these endpoints to loopback or private network origins when authentication is disabled.

Affected products

  • nesquena Hermes WebUI < 0.51.788

Timeline

  • 2026-06-30: patched: Fix committed to repository
  • 2026-07-01: advisory: Release v0.51.788 published
  • 2026-07-09: disclosed: CVE-2026-58123 published

References

Related threats