Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-86124: AutoAgent lets anyone run commands as admin via open TCP port

CVE-2026-86124 · published today
Summary

The AutoAgent program listens on a network port that is reachable from anywhere and runs any commands it receives with full system privileges. An attacker could connect to this port, run any code they want, and potentially access files on the host machine. Close or restrict the port and apply updates that require authentication before executing commands.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
hkuds autoagent <= 16c12b052ef2330a198063c62a07a7f9723031e3
Original advisory text
AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published5 Sep 2026
Updated5 Sep 2026
First seen5 Sep 2026
Sources
CVE-2026-86124 · MITRE
Monitor software like this
Free during beta