PT-2026-106750 · Microsoft · Ufo

CVE-2026-105793

·

Published

2026-10-06

·

Updated

2026-10-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Microsoft UFO versions prior to 3.0.9
Description The press key tool in ufo/client/mcp/http servers/mobile mcp server.py accepts a free-form key code parameter and passes it to adb shell input keyevent. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO MCP API KEY, adb on the host, and a reachable authorized device. This does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges.
Recommendations Update Microsoft UFO to version 3.0.9. As a temporary workaround, restrict the use of the key code parameter in the press key tool.

Exploit

Fix

LPE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105793
GHSA-5CJX-4375-4877

Affected Products

Ufo