PT-2026-71152 · Microsoft · Ufo
CVE-2026-73296
·
Published
2026-08-12
·
Updated
2026-09-01
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Microsoft UFO versions prior to 3.0.8
Description
The
create mobile data collection server and create mobile action server functions in ufo/client/mcp/http servers/mobile mcp server.py expose Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication. This allows an unauthenticated remote attacker to interact with an ADB-connected Android device by invoking the following functions: capture screenshot(), get ui tree(), tap(), swipe(), type text(), launch app(), press key(), and click control(). Consequently, an attacker can disclose screen and device data or modify the device state.Recommendations
Update to version 3.0.8.
As a temporary workaround, restrict access to TCP ports 8020 and 8021 to prevent unauthorized remote access.
Exploit
Fix
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ufo