HIGHAi
Verified
Global

NVD HIGH: CVE-2026-6126 — A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The...

·Source: NIST NVD

Updated:

Executive Summary

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through

Analysis

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVSS Score: 7.3. Published: 2026-04-12T11:16:16.407.

Indicators of Compromise (1)

CVE (1)
CVE-2026-6126
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats

MEDIUMAiNEW

ISMG Editors: Can Humans Still Keep AI Agents in Check?

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-humans-still-keep-ai-agents-in-check-image_small-5-a-32803.jpg" align=right hspace=4><b>Also: AI Agents Breathe New Life in Zero Trust, OpenAI's Chip Puts Nvidia on Notice</b><br>In this week's panel, four ISMG editors discussed the growing challenge of keeping human beings in control of AI agents, what security leade

Bank Info Security
LOWAi

CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

<p><b>Bulletin ID:</b> 2026-111-AWS<br> <b>Scope:</b> AWS<br> <b>Content Type:</b> Important (requires attention)<br> <b>Publication Date:</b> 09/11/2026 12:00 PM PDT</p> <p><b>Description:</b></p> <p>Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents.</p> <p>We identified CVE-2026-89332, where the Kiro agent co

CVE-2026-89332
AWS Security Bulletins
MEDIUMAi

AI Agents Used in PaperCut Attacks on 395 Organizations

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-agents-used-in-papercut-attacks-on-395-organizations-image_small-4-a-32801.jpg" align=right hspace=4><b>GreyNoise Says Attacker Used Hundreds of Agents in 48-Country Campaign</b><br>A likely Russian-speaking attacker used hundreds of AI agents to exploit PaperCut systems, compromising at least 440 systems at 395 organizations i

Bank Info Security