PT-2026-32158 · Zhayujie · Chatgpt-On-Wechat Cowagent

Yu_Bao

·

Published

2026-04-12

·

Updated

2026-04-12

·

CVE-2026-6126

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zahayujie chatgpt-on-wechat CowAgent version 2.0.4
Description A weakness exists in the Administrative HTTP Endpoint component of zhayujie chatgpt-on-wechat CowAgent version 2.0.4 due to missing authentication in an unknown function. This allows for remote attacks. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-6126

Affected Products

Chatgpt-On-Wechat Cowagent