{"apiVersion":"1.0","identifier":"CVE-2026-73296","description":"Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.","publishedAt":"2026-08-12T17:17:32","lastModifiedAt":"2026-08-13T15:20:13","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73296","cvssScore":9.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","epssProbability":0.02609,"riskScore":1.16,"affectedProduct":"Microsoft UFO","affectedVersions":"<3.0.8","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73296","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73296","en":"https://www.redsauce.net/en/cves/CVE-2026-73296","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73296","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73296","de":"https://www.redsauce.net/de/cves/CVE-2026-73296","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73296","el":"https://www.redsauce.net/el/cves/CVE-2026-73296"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73296"}}