Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-6832

Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSON files on the host system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 37.3%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-6832


Contact Us

Shodan ® - All rights reserved