Junglewise Threat Intelligence

CVE-2026-46414: Microsoft UFO role spoofing and task hijacking in WebSocket control plane

CVE-2026-46414 · Severity: high · CVSS 8.8 · Published 2026-05-27

Technologies: Microsoft UFO. Vendors: Microsoft.

Executive brief

Microsoft UFO is an open-source framework used for automating tasks across different devices and platforms. A security flaw in its communication system allows an authorized user to impersonate a high-privilege controller. This enables an attacker to hijack other connected devices, send them unauthorized commands, or disrupt the operations of other users by overwriting their active sessions.

Technical details

The vulnerability exists in the WebSocket control plane of Microsoft UFO (specifically within `ufo/server/ws/handler.py`). The server fails to enforce the role and identity established during the initial connection registration, instead trusting 'client_type' and 'target_id' fields provided in subsequent TASK messages. An attacker with a valid server token can register as a standard device and then send messages claiming the 'constellation' role to dispatch tasks to any other connected device. Additionally, the `ClientConnectionManager` lacks uniqueness checks, allowing an attacker to overwrite existing client registrations by reusing a `client_id`. This combination of flaws allows for unauthorized task execution on peer devices and session hijacking.

Affected products

  • Microsoft UFO 3.0.1-4-ge2626659

Timeline

  • 2026-05-14: advisory: GitHub Security Advisory published
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats