CVE-2026-86121 PUBLISHED

Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 05.09.2026 Updated: 05.09.2026

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor trycua
Product cua-computer-server
Versions Default: unaffected
  • affected from 0 to 0.3.42 (excl.)

Credits

  • George Chen reporter

References

Problem Types

  • Missing Authentication for Critical Function CWE