CVE-2026-62316
Microsoft UFO: DNS Rebinding โ Unauthenticated File Read / Command Execution
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8.
| CWE | CWE-200 CWE-346 |
| Vendor | microsoft |
| Product | ufo |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for microsoft ufo
Be the first to know when new high vulnerabilities affecting microsoft ufo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
microsoft / UFO
< 3.0.8