Command Injection in Microsoft UFO Framework Affects Windows Users
CVE-2026-105791

7.5HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105791?

The Microsoft UFO framework, an open-source tool for intelligent automation, is susceptible to a command injection vulnerability in the run_shell tool of the CommandLineExecutor component. This flaw affects all versions prior to 3.0.9. The vulnerability arises due to inadequate validation of the bash_command parameter, which permits the execution of explorer.exe. Since explorer.exe can delegate path arguments to ShellExecute, a malicious agent could exploit this weakness, allowing unauthorized execution of arbitrary executables or scripts under the privileged context of the desktop user. This exploitation relies on a user running an affected agent workflow and can potentially allow attackers to access or manipulate sensitive files, tokens, and active sessions of the user. The issue has been resolved in version 3.0.9.

Affected Version(s)

UFO < 3.0.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.