← Back to CVE List
Vulnerability Intelligence Report
Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution

CVE-2026-62316

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8.

Information Disclosure No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-200 ↗CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-346 ↗CWE-346: Origin Validation Error

Affected Products & Versions

Vendor Product Affected Versions
microsoft UFO < 3.0.8 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.316%
Vulnerability Class
Information Disclosure

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-07-13T19:27:58
Published2026-08-21T20:17:21
Last Updated2026-08-25T14:19:38

LINK COPIED TO CLIPBOARD