CVE-2026-108682
Received
Received - Intake
Denial of Service in CowAgent Web Console
Vulnerability report for CVE-2026-108682, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-11
Last updated on: 2026-10-11
Assigner: VulDB
Description
Description
A weakness has been identified in zhayujie CowAgent up to 2.1.6. The affected element is the function read of the file /upload of the component Web Console. This manipulation causes denial of service. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zhayujie | CowAgent | 2.1.0 |
| zhayujie | CowAgent | 2.1.1 |
| zhayujie | CowAgent | 2.1.2 |
| zhayujie | CowAgent | 2.1.3 |
| zhayujie | CowAgent | 2.1.4 |
| zhayujie | CowAgent | 2.1.5 |
| zhayujie | CowAgent | 2.1.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-404 | The product does not release or incorrectly releases a resource before it is made available for re-use. |