Junglewise Threat Intelligence

CVE-2026-6126: zhayujie chatgpt-on-wechat missing authentication in CowAgent

CVE-2026-6126 · Severity: high · CVSS 7.3 · Published 2026-04-12

Technologies: Zhayujie CowAgent. Vendors: Zhayujie.

Executive brief

A security vulnerability has been identified in CowAgent, a component of the chatgpt-on-wechat project. The administrative interface fails to properly verify user identity, allowing unauthorized individuals to access management functions remotely. This could lead to unauthorized configuration changes or disruption of the chatbot service.

Technical details

A missing authentication vulnerability (CWE-306) exists in the Administrative HTTP Endpoint of zhayujie chatgpt-on-wechat CowAgent version 2.0.4. The flaw allows a remote, unauthenticated attacker to access administrative functions without providing valid credentials. This is due to improper authentication checks within the web-based management component. An exploit for this vulnerability has been released publicly. As of the advisory date, the project maintainers have not yet released a patch or official response to the issue report.

Affected products

  • zhayujie CowAgent 2.0.4

Timeline

  • 2026-04-12: advisory: Initial disclosure by VulDB and NVD
  • 2026-04-12: disclosed: Public exploit made available

References