CVE-2026-53871
Published Jun 17, 2026Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile…
- evidence mentions
- 5
- Buzz score
- 24.4