Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86124

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Sep 05, 2026
Vendor unknown

Description

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

References