HKUDS AutoAgent TCP Command Server Unauthenticated Remote Code Execution (CVE-2026-86124)
Release Date: 5th September 2026
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations, System/Network administrators, and software development or AI/ML engineering teams that use HKUDS AutoAgent. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-86124 is a critical, unauthenticated remote code execution vulnerability in AutoAgent, an open-source "Fully-Automated and Zero-Code LLM Agent Framework" developed by HKUDS (the Data Intelligence Lab at the University of Hong Kong), with over 9,700 GitHub stars.
What are the systems affected?
The following version(s) are affected:
HKUDS AutoAgent, all current versions/builds – (Affected)
What does this mean?
Typical attack flow:
- Reach the exposed TCP command server — Because the sandbox's command server binds to all network interfaces by default and requires no authentication, any attacker able to reach a deployed AutoAgent instance on its exposed port can connect directly, without presenting any credentials.
- Execute arbitrary commands as root inside the sandbox, and potentially beyond it — The attacker sends shell commands directly to the exposed command server, which executes them as root inside the container; because a host directory is bind-mounted into the container as writable, a successful attacker may also be able to affect files on the underlying host, escaping the intended sandbox isolation.
Attack vectors:
- A network-based, unauthenticated attack against any reachable AutoAgent sandbox instance: a developer workstation, a CI/CD runner, or a cloud host – with the default network binding in place.
- No user interaction, no privileges, and no special access conditions are required (CVSS AV:N/AC:L/PR:N/UI:N).
Successful exploitation may allow attackers to:
- Gain arbitrary, root-level command execution inside the affected AutoAgent sandbox container.
- Leverage the container's writable bind-mounted host directory to affect files on the underlying host machine, effectively escaping the intended sandbox isolation, and use the compromised environment as a foothold into a broader development or AI infrastructure network.
Mitigation process?
CERTVU recommends the following:
-
Restrict Network Exposure Immediately
No vendor patch is currently available. Bind the command server and any other exposed AutoAgent ports to loopback (127.0.0.1) only rather than all interfaces, do not publish the container's command port beyond localhost, run the container as a non-root user where the framework allows it, and mount host directories read-only unless write access is specifically required. This is a workaround, not a fix. The underlying missing-authentication flaw remains present in the software. -
Treat as Urgent
Treat this as urgent alongside similar AI-agent sandbox tooling in the environment. -
Audit the Estate
Audit the estate for AutoAgent and similar AI-agent sandbox deployments. -
Monitor for a Vendor Fix
Monitor for a vendor fix and apply it once released. -
Isolate or Decommission Exposed Instances
Consider isolating or decommissioning exposed instances if they cannot be adequately restricted.
Report suspected compromise to CERTVU at
Reference
- Download advisory (English): CVE-2026-86124_HKUDS AutoAgent TCP Command Server Unauthenticated Remote Code Execution