PT-2026-86395 · Autoagent · Autoagent

·

CVE-2026-86124

·

Published

2026-09-05

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AutoAgent (affected versions not specified)
Description An unauthenticated remote code execution issue exists in the TCP server that binds to all interfaces. This allows an attacker to connect to the exposed communication port and execute arbitrary bash commands as root within the container, which can lead to unauthorized access to bind-mounted host workspace directories.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86124

Affected Products

Autoagent