What is CVE-2026-18992?
An incorrect authorization vulnerability was detected in zhayujie CowAgent up to version 2.1.1, affecting the `_select_tools` function in `agent/evolution/executor.py` of the Self-Evolution Review Agent component. This could allow unauthorized manipulation and potential compromise. Users are advised to apply security updates promptly.
Azərbaycanca: zhayujie CowAgent-in 2.1.1-ə qədər versiyalarında, `agent/evolution/executor.py` faylındakı `_select_tools` funksiyasında səlahiyyətin düzgün yoxlanılmaması zəifliyi aşkarlanıb. Bu, Self-Evolution Review Agent komponentinə təsir edir və icazəsiz əməliyyatlara yol aça bilər. İstifadəçilərə təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which component of CowAgent does CVE-2026-18992 affect?
The vulnerability affects the Self-Evolution Review Agent component of CowAgent.
What action is recommended to mitigate this vulnerability?
Users are advised to apply security updates promptly.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.