cvedb.io
CVE-2026-6832
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2026-04-21T22:16:21.040 · Last modified 2026-06-17T11:01:24.450

Summary

Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSON files on the host system.

Affected products

get-hermes — hermes_web_ui

Does this affect you?

Add your gear to cvedb and we'll alert you only when get-hermes ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.