CRITICAL 9.3 NVD

CVE-2026-86121

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allo

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.

References

Published: 2026-09-05 · Source: NVD · Feed updated: 2026-09-05
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-05 via NVD.

Risk Timeline

CVE Disclosed2026-09-05 · -1 days ago

Remediation Resources

vulnfeed aggregates 10223 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.