Executive brief
Microsoft UFO is an open-source framework used for automating tasks across different devices and platforms. A security flaw in its communication system allows an authorized user to impersonate a high-privilege controller. This enables an attacker to hijack other connected devices, send them unauthorized commands, or disrupt the operations of other users by overwriting their active sessions.
Technical details
The vulnerability exists in the WebSocket control plane of Microsoft UFO (specifically within `ufo/server/ws/handler.py`). The server fails to enforce the role and identity established during the initial connection registration, instead trusting 'client_type' and 'target_id' fields provided in subsequent TASK messages. An attacker with a valid server token can register as a standard device and then send messages claiming the 'constellation' role to dispatch tasks to any other connected device. Additionally, the `ClientConnectionManager` lacks uniqueness checks, allowing an attacker to overwrite existing client registrations by reusing a `client_id`. This combination of flaws allows for unauthorized task execution on peer devices and session hijacking.
Affected products
- Microsoft UFO 3.0.1-4-ge2626659
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE published to NVD