LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6832 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 21, 2026

Hermes WebUI - Broken Access Control

Published: April 21, 2026Updated: April 21, 2026Remote Exploitable

Overview

Hermes WebUI contains an arbitrary file deletion vulnerability caused by unvalidated session_id parameter in /api/session/delete endpoint, letting authenticated attackers delete files outside the session directory.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can delete arbitrary files on the host system, potentially disrupting service or deleting critical data.

Mitigation

Update to the latest version with proper session_id validation and path sanitization.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 21, 2026

🟠 CVE-2026-6832 - High (8.1) Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the ses... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-6832/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 21, 2026

🟠 CVE-2026-6832 - High (8.1) Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the ses... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-6832/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-6832
Severity
High
CVSS Score
8.1
Type
path_traversal
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days