WebSocket Vulnerability in Microsoft UFO Framework for Intelligent Automation
CVE-2026-46416

6.3MEDIUM

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-46416?

The Microsoft UFO framework has a vulnerability related to its handling of WebSocket connections. In version 3.0.1-4-ge2626659, a shared instance of UFOWebSocketHandler is utilized for multiple authenticated connections. This design flaw allows mutable instance fields to be overwritten with each new connection, resulting in protocol objects being inconsistently bound to the originating clients. Consequently, this misconfiguration exposes clients to potential data leakage, where responses intended for one client may inadvertently be sent to another.

Affected Version(s)

UFO 3.0.1-4-ge2626659

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.