๐Ÿ” CVE Alert

CVE-2026-46544

MEDIUM 5.3

Microsoft UFO reuses client-supplied WebSocket session IDs and replays stale task results to new authenticated requesters

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
9th

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an existing in-memory session object if that session_id already exists. If a prior session has completed and remains in memory with populated results, a different authenticated client can send a new TASK message using the same session_id. The server re-enters the existing session object and sends the stale stored result to the new requester through the normal send_task_end() callback path. This is an authenticated cross-client stale result replay issue. The issue requires that the attacker knows or can predict a live or recently completed session_id.

CWE CWE-639
Vendor microsoft
Product ufo
Ecosystems
Industries
TechnologyEnterprise
Published May 27, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft ufo

Be the first to know when new medium vulnerabilities affecting microsoft ufo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

microsoft / UFO
3.0.1-4-ge2626659

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/UFO/security/advisories/GHSA-29gc-vqjp-7fqf