Unauthenticated Remote Command Execution in Cua Computer-Server by TryCua
CVE-2026-86121
9.3CRITICAL
What is CVE-2026-86121?
The Cua computer-server prior to version 0.3.42 is vulnerable to unauthenticated remote command execution due to improper authentication checks when the CONTAINER_NAME environment variable is not set. This critical oversight allows attackers to access the run_command endpoint on TCP port 8000 without authentication, enabling them to execute arbitrary shell commands. Furthermore, the vulnerability permits unauthorized file operations—both reading and writing—exposing sensitive data and system integrity to serious risks. Attackers can gain interactive access to PTY shells, intensifying the potential for exploitation. Immediate updates are recommended to mitigate these risks.
Affected Version(s)
cua-computer-server 0 < 0.3.42
