Unauthenticated Remote Code Execution in AutoAgent by HKUDS
CVE-2026-86124

9.3CRITICAL

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86124?

AutoAgent is vulnerable to unauthenticated remote code execution due to a flaw in its TCP server that binds to all available interfaces. This vulnerability allows an attacker to connect to the exposed TCP communication port and execute arbitrary bash commands as the root user within the container environment. By exploiting this issue, intruders can gain unauthorized access to bind-mounted host workspace directories, potentially compromising the integrity and confidentiality of the affected systems.

Affected Version(s)

AutoAgent 0 <= 16c12b052ef2330a198063c62a07a7f9723031e3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.