CVE-2026-49956: Nesquena Hermes-Webui

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Attackers can send requests to the sessions search handler to retrieve session titles and transcript message content from profiles other than their own active profile.

Affected products

  • Nesquena Hermes-Webui: before 0.51.269 (fixed in 0.51.269)

Published 2026-06-09. Last modified 2026-07-23.