CVE-2026-6126: A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes miss...

Added to the CISA Known Exploited Vulnerabilities catalog on 12 Apr 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.3.

A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made availa...

Required action: Review and patch if applicable to your AI infrastructure.