CRITICAL 9.3 NVD
CVE-2026-86121
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allo
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.
References
- https://github.com/trycua/cua
- https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/computer_serve
- https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/computer_serve
- https://github.com/trycua/cua/commit/59cf25c0ec54
- https://github.com/trycua/cua/issues/1892
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-05 via NVD.
Risk Timeline
CVE Disclosed2026-09-05 · -1 days ago
Remediation Resources
vulnfeed aggregates 10223 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.