Remote Code Execution Vulnerability in Microsoft UFO Framework
CVE-2026-73297
6.9MEDIUM
What is CVE-2026-73297?
The Microsoft UFO framework, a tool for intelligent automation, has a security misconfiguration that affects versions prior to 3.0.8. Specifically, the function responsible for URL security failed to block specific NAT64 prefixes, 6to4, and Teredo prefixes. This oversight allows an unauthenticated remote attacker to manipulate URLs, bypassing the SSRF guard. As a result, attackers could potentially access sensitive cloud metadata and internal services, including localhost resources. Users are encouraged to update to version 3.0.8 or later to mitigate this vulnerability.
Affected Version(s)
UFO < 3.0.8