Vulnerability Description
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/nesquena/hermes-webui/commit/4d90577e25d5537cb07290eca3fb8abf
- https://github.com/nesquena/hermes-webui/pull/4171
- https://github.com/nesquena/hermes-webui/pull/4267
- https://github.com/nesquena/hermes-webui/releases/tag/v0.51.442
- https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-passkey-regist
FAQ
What is CVE-2026-55196?
CVE-2026-55196 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_...
How severe is CVE-2026-55196?
CVE-2026-55196 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-55196?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.