CVE-2026-86124

Source
https://cve.org/CVERecord?id=CVE-2026-86124
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86124.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86124
Published
2026-09-05T09:59:12Z
Modified
2026-10-08T02:52:27Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server
Details

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86124.json"
}
References

Affected packages

Git / github.com/HKUDS/AutoAgent

Affected ranges

Type
GIT
Repo
https://github.com/HKUDS/AutoAgent
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86124.json"