{"id":"CVE-2026-6832","summary":"Nesquena Hermes WebUI Arbitrary File Deletion via Unvalidated session_id","details":"Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSON files on the host system.","modified":"2026-07-16T03:48:47.674003710Z","published":"2026-04-21T21:44:55.301Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6832.json","unresolved_ranges":[{"extracted_events":[{"fixed":"PR #409"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"pr #409"}],"source":"CPE_FIELD"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6832.json"},{"type":"ADVISORY","url":"https://github.com/nesquena/hermes-webui/releases/tag/v0.50.132"},{"type":"ADVISORY","url":"https://github.com/nesquena/hermes-webui/releases/tag/v0.50.32"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6832"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nesquena-hermes-webui-arbitrary-file-deletion-via-unvalidated-session-id"},{"type":"REPORT","url":"https://github.com/nesquena/hermes-webui/pull/409"},{"type":"REPORT","url":"https://github.com/nesquena/hermes-webui/pull/412"},{"type":"FIX","url":"https://github.com/nesquena/hermes-webui/commit/3cc5839bf303fa6758bfdac538507407a2929655"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nesquena/hermes-webui","events":[{"introduced":"0"},{"fixed":"3cc5839bf303fa6758bfdac538507407a2929655"},{"fixed":"f6e1612c7e9aab97a0866ca8f3985f1fd99f52f6"}],"database_specific":{"cpe":"cpe:2.3:a:get-hermes:hermes_web_ui:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.50.32"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.50.131","v0.50.130","v0.50.129","v0.50.128","v0.50.127","v0.50.126","v0.50.125","v0.50.124","v0.50.123","v0.50.122","v0.50.121","v0.50.120","v0.50.119","v0.50.118","v0.50.117","v0.50.116","v0.50.115","v0.50.114","v0.50.113","v0.50.112","v0.50.111","v0.50.110","v0.50.109","v0.50.108","v0.50.96","v0.50.95","v0.50.94","v0.50.93","v0.50.92","v0.50.91","v0.50.90","v0.50.89","v0.50.88","v0.50.87","v0.50.86","v0.50.85","v0.50.84","v0.50.83","v0.50.82","v0.50.76","v0.50.75","v0.50.74","v0.50.73","v0.50.72","v0.50.71","v0.50.70","v0.50.69","v0.50.68","v0.50.67","v0.50.64","v0.50.63","v0.50.62","v0.50.61","v0.50.60","v0.50.59","v0.50.58","v0.50.57","v0.50.56","v0.50.55","v0.50.54","v0.50.53","v0.50.52","v0.50.51","v0.50.50","v0.50.49","v0.50.48","v0.50.47","v0.50.46","v0.50.45","v0.50.44","v0.50.43","v0.50.42","v0.50.41","v0.50.40","v0.50.39","v0.50.38","v0.50.37","v0.50.36","v0.50.35","v0.50.34","v0.50.33","v0.50.32","v0.50.31","v0.50.30","v0.50.29","v0.50.28","v0.50.27","v0.50.26","v0.50.25","v0.50.24","v0.50.23","v0.50.22","v0.50.21","v0.50.20","v0.50.19","v0.50.18","v0.50.17","v0.50.16","v0.50.15","v0.50.14","v0.50.13","v0.50.12","v0.50.11","v0.50.10","v0.50.9","v0.50.8","v0.50.7","v0.50.6","v0.50.5","v0.50.4","v0.50.3","v0.50.2","v0.50.1","v0.50.0","v0.49.4","v0.49.3","v0.49.2","v0.49.1","v0.49.0","v0.48.2","v0.48.1","v0.48.0","v0.47.1","v0.47.0","v0.46.0","v0.45.0","v0.44.1","v0.44.0","v0.43.1","v0.43.0","v0.42.2","v0.42.1","v0.42.0","v0.41.0","v0.40.2","v0.40.1","v0.40.0","v0.39.1","v0.39.0","v0.38.6","v0.38.5","v0.38.4","v0.38.3","v0.38.2","v0.38.1","v0.38.0","v0.37.0","v0.36.3","v0.36.2","v0.36.1","v0.36","v0.35.1","v0.35","v0.34.3","v0.34.2","v0.34.1","v0.34","v0.33","v0.32","v0.31.2","v0.31.1","v0.31","v0.30.4","v0.30.3","v0.30.2","v0.30.1","v0.30","v0.29","v0.28.1","v0.28","v0.27","v0.26","v0.25","v0.24","v0.23","v0.22","v0.21","v0.20","v0.19","v0.18.1","v0.18","v0.17.3","v0.17.2","v0.17.1","v0.16.2","v0.16.1","v0.16","v0.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6832.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}