Denial of Service in Microsoft UFO Prior to Version 3.0.9
CVE-2026-105792

6.5MEDIUM

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105792?

The issue in Microsoft UFO arises from a flaw in the /api/task_result/{task_name} endpoint, which uses a non-reentrant lock when handling certain session-related operations. An authenticated user who possesses knowledge of or can create a specific task name can inadvertently (or purposefully) block the server's request processing indefinitely. This blockage impedes the default single-process server's event loop, effectively halting other critical interactions, including HTTP and WebSocket communications. It's crucial to note that task names that do not map to a session are unaffected by this issue. The problem has been remedied in version 3.0.9 of the product.

Affected Version(s)

UFO < 3.0.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.