Description
A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint. The manipulation results in missing authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in zhayujie CowAgent allows manipulation of a channel function within the Message Endpoint module, resulting in a missing authorization check. This flaw permits an attacker to attempt unauthorized actions on the endpoint, potentially reading, modifying, or deleting messages that should be protected. The impact is unauthorized access, as indicated by CWE‑862 (Missing Authorization) and CWE‑863 (Missing Access Control).

Affected Systems

All instances of zhayujie CowAgent version 2.1.0 or earlier are affected. The attack vector is through the Message Endpoint component in the channel.py file. Administrators should confirm the version in use and note that the vendor has not yet released a fix as of the current data.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. An EPSS score of <1% signals a low but non‑zero likelihood of exploitation. Because the exploit has been released publicly, a remote attacker could target vulnerable instances. The vulnerability is not listed in CISA’s KEV catalog. The missing authorization check does not require local compromise, allowing remote manipulation of the messaging interface.

Generated by OpenCVE AI on July 29, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official patch or upgrade CowAgent to a non‑vulnerable version once the vendor releases it.
  • Restrict external access to the Message Endpoint by configuring network firewalls or ACLs so that only trusted hosts can communicate with it.
  • If the Message Endpoint component is unnecessary for your operations, disable or remove it to eliminate the attack surface.
  • Monitor system logs for abnormal endpoint traffic or unauthorized requests.

Generated by OpenCVE AI on July 29, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint. The manipulation results in missing authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title zhayujie CowAgent Message Endpoint channel.py authorization
First Time appeared Zhayujie
Zhayujie cowagent
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:zhayujie:cowagent:*:*:*:*:*:*:*:*
Vendors & Products Zhayujie
Zhayujie cowagent
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Zhayujie Cowagent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-10T15:17:55.107Z

Reserved: 2026-07-09T18:37:50.069Z

Link: CVE-2026-15332

cve-icon Vulnrichment

Updated: 2026-07-10T15:17:51.746Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses