CVE-2026-6832 is an arbitrary file deletion vulnerability in Hermes WebUI affecting the /api/session/delete endpoint. Authenticated attackers can exploit insufficient input validation on the session_id parameter to supply absolute paths or path traversal sequences, enabling deletion of JSON files outside the intended session directory and across the host system. This allows malicious authenticated users to destroy critical files with write permissions. The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) with a network-based attack vector, low complexity, and requirements for low privileges. While confidentiality is not impacted, the integrity and availability impacts are rated as HIGH, reflecting the ability to delete arbitrary writable files. The EPSS score of 0.0009 indicates this vulnerability is currently in the lower percentile for exploitation probability across the CVE ecosystem. Exploitation status shows no active real-world attacks documented. The vulnerability does not appear on the CISA KEV catalog and remains inactive on threat intelligence hot lists, suggesting minimal current threat actor interest. However, the straightforward nature of the exploitation method warrants prompt patching by organizations running vulnerable Hermes WebUI deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.50.32CPE matchmatch criteria | cpe:2.3:a:get-hermes:hermes_web_ui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.