Unauthorized Remote Access Vulnerability in Microsoft UFO Automation Framework
CVE-2026-73296

9.4CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73296?

The Microsoft UFO automation framework prior to version 3.0.8 has a significant vulnerability that exposes its HTTP MCP services on TCP ports 8020 and 8021 without adequate authentication mechanisms. This flaw allows an unauthenticated remote attacker to execute a range of controlling commands on ADB-connected Android devices. Attackers can capture screenshots, retrieve UI tree structures, simulate taps and swipes, input text, launch applications, send keystrokes, and manipulate various device controls, potentially leading to unauthorized access to sensitive screen and device information. This critical issue has been resolved in version 3.0.8.

Affected Version(s)

UFO < 3.0.8

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.