CVE-2026-55196
Last modified
CVE-2026-55196 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST /api/auth/passkey/register endpoints are accessible without authentication, allowing attackers to claim the first passkey and gain permanent administrative control.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55196?
How severe is CVE-2026-55196?
How do I fix CVE-2026-55196?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55175Spinnaker is an open source, multi-cloud continuous delivery…7.5
- CVE-2026-55180pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm…6.5
- CVE-2026-55187Mailpit is an email testing tool and API for developers. Pri…5.8
- CVE-2026-55188RustFS is a distributed object storage system built in Rust.…8.2
- CVE-2026-55189RustFS is a distributed object storage system built in Rust.…7.7
- CVE-2026-55195py7zr is a Python-based library and utility to support 7zip …8.7
- CVE-2026-55197Hermes WebUI before 0.51.443 contains a broken access contro…7.1
- CVE-2026-55198Hermes WebUI before 0.51.443 contains an authorization bypas…7.1
- CVE-2026-55199libssh2 through 1.11.1, fixed in commit 1762685, contains a …7.5
- CVE-2026-55200libssh2 through 1.11.1, fixed in commit 7acf3df contains an …8.3
- CVE-2026-55201Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a …7.4
- CVE-2026-55202Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to …8.8
Are you affected by CVE-2026-55196?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
