By weakness (CWE)
CWE-565: related vulnerabilities
CVEs classified under CWE-565. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-53871HIGH 8.1
Hermes WebUI versions before 0.51.368 have an authorization flaw that allows an authenticated attacker to impersonate other user profiles. The vulnerability exists in how the application validates the hermes_profile cookie—it trusts user-supplied profile names without properly verifying that the requester owns or has permission to access those profiles. An attacker who is already logged in could modify this cookie to view, modify, or access files and sessions belonging to other users on the system.