← back
CVE-2026-55196

Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass

CVSS 9.1 CRITICALEPSS 0.6%CWE-306
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
17 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →