{"id":"CVE-2026-55196","title":"Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys","summary":"Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no ex…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-306"],"vendor":"hermes-webui","product":"hermes-webui","affected":["hermes-webui < 0.51.409"],"published":"2026-06-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T18:16:48.030","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55196","references":[{"url":"https://github.com/nesquena/hermes-webui/commit/4d90577e25d5537cb07290eca3fb8abff3bab316","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/pull/4171","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/pull/4267","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/releases/tag/v0.51.442","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hermes-webui-unauthenticated-passkey-registration-via-authentication-bypass","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-06-23T02:02:11.438761Z"},"epss":0.00579,"epssPercentile":0.46089,"ingestedAt":"2026-09-17T18:25:15.969Z","slug":"CVE-2026-55196","body":"## Overview\n\nHermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}