{"apiVersion":"1.0","identifier":"CVE-2026-62316","description":"Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim-s user. This issue is fixed in version 3.0.8.","publishedAt":"2026-08-21T21:17:01","lastModifiedAt":"2026-08-25T15:16:35","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62316","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","epssProbability":0.00316,"riskScore":0.91,"affectedProduct":"Microsoft UFO","affectedVersions":"<3.0.8","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-62316","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-62316","en":"https://www.redsauce.net/en/cves/CVE-2026-62316","fr":"https://www.redsauce.net/fr/cves/CVE-2026-62316","pt":"https://www.redsauce.net/pt/cves/CVE-2026-62316","de":"https://www.redsauce.net/de/cves/CVE-2026-62316","sk":"https://www.redsauce.net/sk/cves/CVE-2026-62316","el":"https://www.redsauce.net/el/cves/CVE-2026-62316"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-62316"}}