Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-86121: Cua computer-server before 0.3.42 lets anyone run commands
CVE-2026-86121 · published today
Summary
Versions of Cua computer-server older than 0.3.42 open a network port without requiring a password, so anyone who can reach that port can tell the server to run commands, read or change files, and open an interactive shell. This gives an attacker the ability to take control of the server and access its data. Upgrade to version 0.3.42 or later, and until you can update, block external access to the port with a firewall or limit it to trusted computers.
What to do
- Update trycua cua-computer-server to version 0.3.42 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| trycua | cua-computer-server | < 0.3.42 |
Original advisory text
Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.
References
- https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/comp... technical-description
- https://github.com/trycua/cua/issues/1892 issue-tracking
- https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/comp... technical-description
- https://github.com/trycua/cua/commit/59cf25c0ec54 patch
- https://github.com/trycua/cua product
- https://www.vulncheck.com/advisories/cua-computer-server-before-0.3.42-unauthent... third-party-advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published5 Sep 2026
Updated5 Sep 2026
First seen5 Sep 2026
Monitor software like this
Free during beta