Unauthenticated Remote Command Execution in Cua Computer-Server by TryCua
CVE-2026-86121

9.3CRITICAL

Key Information:

Vendor

Trycua

Vendor
CVE Published:
5 September 2026

What is CVE-2026-86121?

The Cua computer-server prior to version 0.3.42 is vulnerable to unauthenticated remote command execution due to improper authentication checks when the CONTAINER_NAME environment variable is not set. This critical oversight allows attackers to access the run_command endpoint on TCP port 8000 without authentication, enabling them to execute arbitrary shell commands. Furthermore, the vulnerability permits unauthorized file operations—both reading and writing—exposing sensitive data and system integrity to serious risks. Attackers can gain interactive access to PTY shells, intensifying the potential for exploitation. Immediate updates are recommended to mitigate these risks.

Affected Version(s)

cua-computer-server 0 < 0.3.42

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.