No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 26 Jul 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue. | |
| Title | NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control | |
| First Time appeared |
Nousresearch
Nousresearch hermes-agent |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nousresearch
Nousresearch hermes-agent |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-07-26T00:15:11.157Z
Reserved: 2026-07-25T10:42:39.965Z
Link: CVE-2026-17432
No data.
No data.
No data.
OpenCVE Enrichment
No data.