Path Traversal Vulnerability in Microsoft UFO Automation Framework
CVE-2026-46402
8.1HIGH
What is CVE-2026-46402?
Microsoft's UFO open-source framework for intelligent automation has a path traversal vulnerability in version 3.0.1-4-ge2626659. This issue allows authenticated users to manipulate the task_name value, enabling them to create log directories and files outside the designated logs/ directory. The exploit could lead to unauthorized access to system files and compromise the integrity of the application’s logging mechanism.
Affected Version(s)
UFO 3.0.1-4-ge2626659