CRITICALCVSS 9.8Vulnerability

CVE-2026-86121

Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.

Properties

severity
CRITICAL
cvss_severity
CRITICAL
cvss_score
9.8
retrieved_at
2026-09-25T15:10:08+00:00
score
9.8
last_source
NVD
cve_id
CVE-2026-86121
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-25T15:10:08+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-05T10:16:43.463
last_modified
2026-09-24T20:43:32.537

Related Entities (2)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Missing Authentication for Critical Function

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86121 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal