CVE-2026-86124: AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server

Published Sep 5, 2026
·
Updated

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

Affected Software

1 affected component
AutoAgent

Event History

Sep 5, 2026
CVE Published
via MITRE·09:59 AM
Data Sourced
via MITRE·09:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to remote exploitation?

Deployments are exposed when the Sandbox TCP command server is reachable over the network. The server binds to all interfaces, so any environment that exposes or routes traffic to its communication port is at risk.

2

Does exploitation require credentials or user interaction?

No. The vulnerability is unauthenticated and can be exploited remotely with no privileges or user interaction required.

3

What access can an attacker obtain after exploitation?

An attacker can submit arbitrary bash commands that execute as root inside the container. They can also access host workspace directories that are bind-mounted into that container.

4

What can be done while a fix is unavailable?

Prevent untrusted networks from reaching the Sandbox TCP communication port. Restrict access to trusted hosts or isolate the service so the port is not externally reachable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203