← العودة للجدول
CVE-2026-49973
CVE-2026-49973 — Hermes WebUI before version 0.51.358 contains an improper access control vulnera
📅 2026-06-11
🔴 Critical 🔥 No NVD Exploit Vulnerability CVSS 9.4

📋 الوصف الكامل

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an a

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-49973

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v0.51.358

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←