# CVE-2026-82020

## Summary

- **CVE ID:** CVE-2026-82020
- **Severity:** HIGH
- **CVSS Score:** 7.6 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-552
- **Published:** Aug 28, 2026
- **Last Modified:** Sep 1, 2026

## Description

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.

## Affected Products

- NousResearch — hermes-agent (0.16.0)
- NousResearch — hermes-agent (2026.6.5)

## References

- [CNA](https://github.com/NousResearch/hermes-agent/releases/tag/v2026.6.19)
- [CNA](https://github.com/NousResearch/hermes-agent/pull/45821)
- [CNA](https://github.com/NousResearch/hermes-agent/commit/da28d5d113956dcf803d5cff552a120740a96a59)
- [CNA](https://github.com/NousResearch/hermes-agent/commit/2b67e96aec2aa2abd5e94b544cda8e564c75f9f5)
- [CNA](https://www.vulncheck.com/advisories/hermes-agent-credential-store-overwrite-via-file-write-tool)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 25.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._