Junglewise Threat Intelligence

CVE-2026-85105: NousResearch hermes-agent authorization bypass in Session Management

CVE-2026-85105 · Severity: high · CVSS 7.3 · Published 2026-09-03

Technologies: NousResearch Hermes Agent. Vendors: NousResearch.

Executive brief

NousResearch hermes-agent is a software component used for managing agent sessions. A flaw in its session management allows attackers to bypass authorization checks by manipulating the session_id parameter, potentially granting unauthorized access to protected functionality. This vulnerability can be exploited remotely without authentication.

Technical details

The vulnerability is an authorization bypass (CWE-307/CWE-863) in the _sess_nowait function within s71.py of hermes-agent's Session Management component. The flaw allows attackers to manipulate the session_id argument to circumvent authorization controls. The attack vector is network-based and requires no prior authentication. An attacker can remotely exploit this to gain unauthorized access to session-protected resources or operations. No patch information is currently available as the vendor did not respond to early disclosure attempts.

Affected products

  • NousResearch hermes-agent 0.18.0

Timeline

  • 2026-09-03: disclosed

References

Related threats