Remote Code Execution Vulnerability in Microsoft UFO Framework
CVE-2026-73297

6.9MEDIUM

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73297?

The Microsoft UFO framework, a tool for intelligent automation, has a security misconfiguration that affects versions prior to 3.0.8. Specifically, the function responsible for URL security failed to block specific NAT64 prefixes, 6to4, and Teredo prefixes. This oversight allows an unauthenticated remote attacker to manipulate URLs, bypassing the SSRF guard. As a result, attackers could potentially access sensitive cloud metadata and internal services, including localhost resources. Users are encouraged to update to version 3.0.8 or later to mitigate this vulnerability.

Affected Version(s)

UFO < 3.0.8

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.