Tag
critical
advisory
Pelican Web UI Privilege Escalation Vulnerability
2 rules 1 TTP 1 IOCA privilege escalation vulnerability in Pelican WebUI versions v7.21 to v7.24 allows authenticated users to gain admin privileges by manipulating database records, potentially leading to configuration modification, API token creation, and password changes.
pelicanplatform/pelican +1
privilege-escalation
webui
pelican
2r
1t
1i
high
advisory
Hermes WebUI Arbitrary File Deletion Vulnerability (CVE-2026-6832)
2 rules 1 TTP 1 CVEHermes WebUI is vulnerable to arbitrary file deletion via path traversal in the /api/session/delete endpoint due to insufficient validation of the session_id parameter, allowing authenticated attackers to delete writable JSON files on the host system.
cve-2026-6832
path-traversal
file-deletion
webui
2r
1t
1c