Executive brief
Hermes WebUI, a management interface for workspace environments, contains a critical flaw in its embedded terminal feature. When the software is used without a password (the default configuration) and exposed to a network, an attacker can gain full control over the server by sending a series of web requests. This allows unauthorized individuals to execute arbitrary commands, potentially leading to complete data theft or system takeover.
Technical details
A missing authentication check (CWE-306) in the embedded terminal API of Hermes WebUI allows unauthenticated remote code execution. The vulnerability exists because the 'check_auth()' function returns True by default when no password or passkey is configured, leaving the terminal endpoints (/api/terminal/start, /api/terminal/input, etc.) accessible to any network caller. An attacker can achieve full command execution as the server process user by making four sequential HTTP requests to initialize a session, attach a PTY shell, and input arbitrary shell commands. The issue is addressed in version 0.51.788 by implementing a local-origin gate that restricts these endpoints to loopback or private network origins when authentication is disabled.
Affected products
- nesquena Hermes WebUI < 0.51.788
Timeline
- 2026-06-30: patched: Fix committed to repository
- 2026-07-01: advisory: Release v0.51.788 published
- 2026-07-09: disclosed: CVE-2026-58123 published