WebSocket Vulnerability in Microsoft UFO Framework for Intelligent Automation
CVE-2026-46416
6.3MEDIUM
What is CVE-2026-46416?
The Microsoft UFO framework has a vulnerability related to its handling of WebSocket connections. In version 3.0.1-4-ge2626659, a shared instance of UFOWebSocketHandler is utilized for multiple authenticated connections. This design flaw allows mutable instance fields to be overwritten with each new connection, resulting in protocol objects being inconsistently bound to the originating clients. Consequently, this misconfiguration exposes clients to potential data leakage, where responses intended for one client may inadvertently be sent to another.
Affected Version(s)
UFO 3.0.1-4-ge2626659