PT-2026-71152 · Microsoft · Ufo

CVE-2026-73296

·

Published

2026-08-12

·

Updated

2026-09-01

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Microsoft UFO versions prior to 3.0.8
Description The create mobile data collection server and create mobile action server functions in ufo/client/mcp/http servers/mobile mcp server.py expose Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication. This allows an unauthenticated remote attacker to interact with an ADB-connected Android device by invoking the following functions: capture screenshot(), get ui tree(), tap(), swipe(), type text(), launch app(), press key(), and click control(). Consequently, an attacker can disclose screen and device data or modify the device state.
Recommendations Update to version 3.0.8. As a temporary workaround, restrict access to TCP ports 8020 and 8021 to prevent unauthorized remote access.

Exploit

Fix

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73296
GHSA-24FQ-M9RR-G3MM

Affected Products

Ufo