Beveiligingsadvies

CVE-2026-49956

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-09 16:10:33
Laatst bijgewerkt 2026-07-14 21:33:28
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Attackers can send requests to the sessions search handler to retrieve session titles and transcript message content from profiles other than their own active profile.