Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft ufo |
|
| Vendors & Products |
Microsoft
Microsoft ufo |
Wed, 12 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8. | |
| Title | Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure | |
| Weaknesses | CWE-306 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T16:29:03.154Z
Reserved: 2026-08-11T19:42:11.450Z
Link: CVE-2026-73296
No data.
Status : Received
Published: 2026-08-12T17:17:32.780
Modified: 2026-08-12T17:17:32.780
Link: CVE-2026-73296
No data.
OpenCVE Enrichment
Updated: 2026-08-12T18:30:06Z