PT-2026-32158 · Zhayujie · Chatgpt-On-Wechat Cowagent

·

CVE-2026-6126

·

Published

2026-04-12

·

Updated

2026-04-12

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zahayujie chatgpt-on-wechat CowAgent version 2.0.4
Description A weakness exists in the Administrative HTTP Endpoint component of zhayujie chatgpt-on-wechat CowAgent version 2.0.4 due to missing authentication in an unknown function. This allows for remote attacks. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6126

Affected Products

Chatgpt-On-Wechat Cowagent