Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6832

28
FAUCET Score

CVE-2026-6832 is an arbitrary file deletion vulnerability in Hermes WebUI affecting the /api/session/delete endpoint. Authenticated attackers can exploit insufficient input validation on the session_id parameter to supply absolute paths or path traversal sequences, enabling deletion of JSON files outside the intended session directory and across the host system. This allows malicious authenticated users to destroy critical files with write permissions. The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) with a network-based attack vector, low complexity, and requirements for low privileges. While confidentiality is not impacted, the integrity and availability impacts are rated as HIGH, reflecting the ability to delete arbitrary writable files. The EPSS score of 0.0009 indicates this vulnerability is currently in the lower percentile for exploitation probability across the CVE ecosystem. Exploitation status shows no active real-world attacks documented. The vulnerability does not appear on the CISA KEV catalog and remains inactive on threat intelligence hot lists, suggesting minimal current threat actor interest. However, the straightforward nature of the exploitation method warrants prompt patching by organizations running vulnerable Hermes WebUI deployments.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.50.32CPE matchmatch criteria
cpe:2.3:a:get-hermes:hermes_web_ui:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.2HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 27th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / nesquena/hermes-webui/commit/3cc5839bf303fa6758bfdac538507407a2929655
Patch
github.com / nesquena/hermes-webui/pull/409
ExploitIssue TrackingPatchVendor Advisory
github.com / nesquena/hermes-webui/pull/412
Issue TrackingPatch
github.com / nesquena/hermes-webui/releases/tag/v0.50.132
ProductRelease Notes
github.com / nesquena/hermes-webui/releases/tag/v0.50.32
ProductRelease Notes
vulncheck.com / advisories/nesquena-hermes-webui-arbitrary-file-deletion-via-unvalidated-session-id
Third Party Advisory