CVE-2026-18773 Details
Description
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
An authorization bypass vulnerability has been identified in NousResearch Hermes-Agent versions through 2026.6.5. The issue resides in the Quick Command Handler, specifically within the _check_slash_access function of gateway/run.py. This vulnerability allows authenticated, allowlisted non-admin users to invoke admin-only quick commands, including those that execute shell commands in the gateway process. The flaw arises because the application does not enforce the same authorization checks for operator-configured quick commands as it does for registered slash commands. As a result, non-admin users can exploit this oversight to access restricted functionalities.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 4, 2026CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/YLChen-007/f0036aa1c410b70f5e41272947180645 | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-18773 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/856874 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/385783 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/385783/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NousResearch hermes-agent | <= 2026.6.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |
Volerion