Security Vulnerability in Microsoft UFO Open-Source Framework for Intelligent Automation
CVE-2026-62316

8.8HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-62316?

The Microsoft UFO open-source framework has a significant vulnerability involving the FastMCP streamable HTTP server which binds to localhost:8010. This vulnerability arises from the lack of validation for the Host, Origin, and Sec-Fetch-Site headers. An attacker can exploit this weakness through a malicious web page via DNS rebinding techniques. This allows them to access the local /mcp endpoint, potentially enumerate tool schemas via the tools/list endpoint, and execute commands using the execute_command function with a valid UFO_MCP_API_KEY. This could lead to unauthorized file access or command execution under the privileges of the victim's user. The issue has been addressed in version 3.0.8, underscoring the importance of keeping products up to date.

Affected Version(s)

UFO < 3.0.8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.