Missing Authentication in zhayujie chatgpt-on-wechat CowAgent
CVE-2026-6126
Key Information:
- Vendor
Zhayujie
- Vendor
- CVE Published:
- 12 April 2026
Badges
What is CVE-2026-6126?
A vulnerability has been discovered in zhayujie chatgpt-on-wechat CowAgent version 2.0.4, specifically in the Administrative HTTP Endpoint. This weakness allows for the possibility of unauthenticated access, enabling potential attackers to execute operations without proper credentials. The exploit is publicly available, raising concerns about its misuse for unauthorized actions. Despite an issue report submitted to the project team, they have yet to respond or address the vulnerability.
Affected Version(s)
chatgpt-on-wechat CowAgent 2.0.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
