Unauthorized Remote Access Vulnerability in Microsoft UFO Automation Framework
CVE-2026-73296

9.4CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73296?

CVE-2026-73296 is a security vulnerability found in the Microsoft UFO Automation Framework, an open-source tool designed for intelligent automation across various devices and platforms. The flaw exists prior to version 3.0.8, where the framework's components—specifically the create_mobile_data_collection_server and create_mobile_action_server functionalities—expose certain services without requiring authentication. This lack of authentication allows an attacker to remotely access an ADB-connected Android device, enabling them to perform various commands, such as capturing screenshots, retrieving user interface elements, and altering device settings. The potential for unauthorized control could lead to significant data exposure and manipulation, ultimately jeopardizing the security and integrity of devices connected through the framework.

Potential impact of CVE-2026-73296

  1. Unauthorized Device Control: The vulnerability allows malicious actors to execute commands on a target Android device without authentication. This could result in unauthorized modifications to device functionality and data, leading to severe privacy breaches or unauthorized access to sensitive information.

  2. Data Exposure: Attackers can utilize this vulnerability to capture screenshots and gather user interface data, potentially exposing personal or confidential information to unauthorized third parties. This compromises user privacy and could lead to further exploitation of sensitive data.

  3. Increased Attack Surface: As the framework is designed for intelligent automation across multiple platforms, the vulnerability creates a significant attack surface, especially in environments where multiple devices are interconnected. This could facilitate broader network compromises, allowing attackers to leverage one vulnerable device to gain access to others within the same ecosystem.

Affected Version(s)

UFO < 3.0.8

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.