CVE-2026-58122: Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by suppl...

Added to the CISA Known Exploited Vulnerabilities catalog on 09 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.1.

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to ...

Required action: Review and patch if applicable to your AI infrastructure.