Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-86121: Cua computer-server before 0.3.42 lets anyone run commands

CVE-2026-86121 · published today
Summary

Versions of Cua computer-server older than 0.3.42 open a network port without requiring a password, so anyone who can reach that port can tell the server to run commands, read or change files, and open an interactive shell. This gives an attacker the ability to take control of the server and access its data. Upgrade to version 0.3.42 or later, and until you can update, block external access to the port with a firewall or limit it to trusted computers.

What to do
  • Update trycua cua-computer-server to version 0.3.42 or later.
Affected software
VendorProductAffected versions
trycua cua-computer-server < 0.3.42
Original advisory text
Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published5 Sep 2026
Updated5 Sep 2026
First seen5 Sep 2026
Sources
CVE-2026-86121 · MITRE
Monitor software like this
Free during beta