Vulnerability record · CVE-2026-6832 · published 21 April 2026
CVE-2026-6832: Get-hermes hermes web ui path traversal vulnerability
GGet Hermes · Hermes Web Ui
Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSON files on the host system.
Description
Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSON files on the host system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/nesquena/hermes-webui/commit/3cc5839bf303fa6758bfdac538507407a2929655 | Patch |
| https://github.com/nesquena/hermes-webui/pull/409 | ExploitIssue TrackingPatchVendor Advisory |
| https://github.com/nesquena/hermes-webui/pull/412 | Issue TrackingPatch |
| https://github.com/nesquena/hermes-webui/releases/tag/v0.50.132 | ProductRelease Notes |
| https://github.com/nesquena/hermes-webui/releases/tag/v0.50.32 | ProductRelease Notes |
| https://www.vulncheck.com/advisories/nesquena-hermes-webui-arbitrary-file-deletion-via-unvalidated-session-id | Third Party Advisory |
Track CVE-2026-6832 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-6832), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.