{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108682", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-10-10T21:22:14.484Z", "datePublished": "2026-10-11T14:15:19.490Z", "dateUpdated": "2026-10-11T14:15:19.490Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-10-11T14:15:19.490Z" }, "title": "zhayujie CowAgent Web Console upload read denial of service", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-404", "lang": "en", "description": "Denial of Service" } ] } ], "affected": [ { "vendor": "zhayujie", "product": "CowAgent", "versions": [ { "version": "2.1.0", "status": "affected" }, { "version": "2.1.1", "status": "affected" }, { "version": "2.1.2", "status": "affected" }, { "version": "2.1.3", "status": "affected" }, { "version": "2.1.4", "status": "affected" }, { "version": "2.1.5", "status": "affected" }, { "version": "2.1.6", "status": "affected" } ], "cpes": [ "cpe:2.3:a:zhayujie:cowagent:*:*:*:*:*:*:*:*" ], "modules": [ "Web Console" ] } ], "descriptions": [ { "lang": "en", "value": "A weakness has been identified in zhayujie CowAgent up to 2.1.6. The affected element is the function read of the file /upload of the component Web Console. This manipulation causes denial of service. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 5.4, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 5.4, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 5.5, "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C" } } ], "timeline": [ { "time": "2026-10-10T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-10-10T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-10-10T23:27:27.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "hackerguopeng (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB CNA Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/416390", "name": "VDB-416390 | zhayujie CowAgent Web Console upload read denial of service", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/416390/cti", "name": "VDB-416390 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-108682", "name": "CVE-2026-108682 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/958012", "name": "Submit #958012 | zhayujie CowAgent 2.1.6 Denial of Service", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/hackerguopeng/cve/tree/main/CowAgent_Web_Upload_File_Directory_DoS_Report", "tags": [ "exploit" ] } ], "x_generator": [ "VulDB PVTS v202610" ] } } }