CyberRota
Back to database

CVE-2026-22677

MEDIUM · CVSS 6.5 EPSS 0.04% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-13 · Last synced: 2026-06-09

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-22677
Severity
MEDIUM
CVSS
6.5
EPSS
0.04%

Original NVD Description

Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted session with an unrestricted workspace value. Attackers can supply a blocked filesystem root in the workspace field and subsequently use relative paths in the session file API to access any file readable by the WebUI process.