Unauthorized Remote Access Vulnerability in Microsoft UFO Automation Framework
CVE-2026-73296
9.4CRITICAL
What is CVE-2026-73296?
The Microsoft UFO automation framework prior to version 3.0.8 has a significant vulnerability that exposes its HTTP MCP services on TCP ports 8020 and 8021 without adequate authentication mechanisms. This flaw allows an unauthenticated remote attacker to execute a range of controlling commands on ADB-connected Android devices. Attackers can capture screenshots, retrieve UI tree structures, simulate taps and swipes, input text, launch applications, send keystrokes, and manipulate various device controls, potentially leading to unauthorized access to sensitive screen and device information. This critical issue has been resolved in version 3.0.8.
Affected Version(s)
UFO < 3.0.8