CVE-2026-86124

Summary

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

Affected Software

VendorProductVersion RangeStatus
HKUDSAutoAgent0 <= 16c12b052ef2330a198063c62a07a7f9723031e3affected

Weaknesses

  • CWE-306: Missing Authentication for Critical Function

References