CVE-2026-108682
Received Received - Intake

Denial of Service in CowAgent Web Console

Vulnerability report for CVE-2026-108682, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A weakness has been identified in zhayujie CowAgent up to 2.1.6. The affected element is the function read of the file /upload of the component Web Console. This manipulation causes denial of service. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
zhayujie CowAgent 2.1.0
zhayujie CowAgent 2.1.1
zhayujie CowAgent 2.1.2
zhayujie CowAgent 2.1.3
zhayujie CowAgent 2.1.4
zhayujie CowAgent 2.1.5
zhayujie CowAgent 2.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service (DoS) weakness in zhayujie CowAgent up to version 2.1.6. The issue occurs in the Web Console's /upload function, where the system reads entire files into memory before saving them to disk. This allows attackers to consume excessive memory and fill disk storage by uploading large files or directories without size or count limits.

Detection Guidance

Monitor for excessive memory usage or disk space consumption by the CowAgent Web Console process. Check for unusually large file uploads or rapid directory creation in the upload directory. Inspect network traffic for repeated POST requests to the /upload endpoint with large payloads.

Impact Analysis

An attacker could exploit this to crash the CowAgent service by consuming all available memory or disk space. This would make the Web Console unresponsive and potentially disrupt any services relying on CowAgent. The attack can be performed remotely if the Web Console is accessible.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial of service attacks that disrupt service availability. GDPR requires data protection and availability, while HIPAA mandates access controls and integrity of health data. Uncontrolled file uploads may lead to unauthorized resource consumption, violating availability requirements and potentially exposing data during service disruptions.

Mitigation Strategies

Restrict access to the CowAgent Web Console to trusted users only. Implement network-level controls to block unauthorized access to the /upload endpoint. Update CowAgent to the latest version if a patch is available. Monitor system resources for signs of abuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108682. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart