Vulnerability in Microsoft UFO Automation Framework Allows File Corruption
CVE-2026-105789

5.4MEDIUM

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105789?

The Microsoft UFO automation framework has a vulnerability in the execute_command tool that permits an authenticated user to erroneously invoke sort or uniq commands in a manner that can lead to unintended file overwrites. Specifically, the vulnerability lies in the handling of command parameters that permit modification of file outputs without properly enforcing argument restrictions. This could potentially corrupt essential configuration files and disrupt service operations. This issue has been rectified in version 3.0.9, emphasizing the need for users to update to this version to ensure security and data integrity.

Affected Version(s)

UFO < 3.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.