Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.
History

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Trycua
Trycua cua-computer-server
Vendors & Products Trycua
Trycua cua-computer-server

Sat, 05 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.
Title Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-09-05T09:59:10.093Z

Updated: 2026-09-08T17:25:54.401Z

Reserved: 2026-09-05T01:59:22.753Z

Link: CVE-2026-86121

cve-icon Vulnrichment

Updated: 2026-09-08T17:25:46.424Z

cve-icon NVD

Status : Received

Published: 2026-09-05T10:16:43.463

Modified: 2026-09-08T18:21:14.990

Link: CVE-2026-86121

cve-icon Redhat

No data.