CVE-2026-17432 Details
Description
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue.
A vulnerability exists in NousResearch Hermes-Agent version 2026.6.5, specifically within the SimpleX Gateway authorization component. The issue arises in the file 'hermes-agent/plugins/platforms/simplex/adapter.py', where improper access controls allow an attacker to manipulate the 'contactId' argument. This vulnerability can be exploited remotely, although it requires a high level of complexity. The issue has been publicly disclosed and is associated with an authorization bypass, allowing unauthorized access to the agent's capabilities.
Users are advised to update to the latest version of NousResearch Hermes-Agent, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 26, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/NousResearch/hermes-agent/ | [email protected] | Vendor |
| https://github.com/NousResearch/hermes-agent/commit/490c486ff65b766d9de0fe0e6f26e1778aaa8fb3 | [email protected] | Source CodeVendor |
| https://github.com/NousResearch/hermes-agent/issues/44729 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/NousResearch/hermes-agent/issues/44730 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/NousResearch/hermes-agent/pull/41246 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-17432 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/862424 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/383065 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/383065/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NousResearch hermes-agent | >= 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3, <= e71d746820bf262214e4e1887683d3f65d211cc1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 26, 2026 | New CVE Received | [email protected] |
Volerion