Unauthenticated Remote Code Execution in AutoAgent by HKUDS
CVE-2026-86124
9.3CRITICAL
What is CVE-2026-86124?
AutoAgent is vulnerable to unauthenticated remote code execution due to a flaw in its TCP server that binds to all available interfaces. This vulnerability allows an attacker to connect to the exposed TCP communication port and execute arbitrary bash commands as the root user within the container environment. By exploiting this issue, intruders can gain unauthorized access to bind-mounted host workspace directories, potentially compromising the integrity and confidentiality of the affected systems.
Affected Version(s)
AutoAgent 0 <= 16c12b052ef2330a198063c62a07a7f9723031e3
