CVE-2026-105793
Last modified
CVE-2026-105793 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`.
Description
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO_MCP_API_KEY, adb on the host, and a reachable authorized device, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.9.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | UFO | < 3.0.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-105793?
How severe is CVE-2026-105793?
How do I fix CVE-2026-105793?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105788Microsoft UFO is an open-source framework for intelligent au…8.8
- CVE-2026-105789Microsoft UFO is an open-source framework for intelligent au…5.4
- CVE-2026-10579A flaw was found in Picketlink Federation SAML; the unsolcit…9.8
- CVE-2026-105790Microsoft UFO is an open-source framework for intelligent au…6.4
- CVE-2026-105791Microsoft UFO is an open-source framework for intelligent au…7.5
- CVE-2026-105792Microsoft UFO is an open-source framework for intelligent au…6.5
- CVE-2026-105794MsQuic is a cross-platform C implementation of the IETF QUIC…9.1
- CVE-2026-105795Kiota is an OpenAPI based HTTP Client code generator. From 1…3.1
- CVE-2026-105796Kiota is an OpenAPI based HTTP Client code generator. From 0…8.8
- CVE-2026-105797SimpleChat is a secure AI conversation application with pers…8.8
- CVE-2026-105798SimpleChat is a secure AI conversation application with pers…8.7
- CVE-2026-105799LangChain is a framework for building LLM-powered applicatio…2.3
Are you affected by CVE-2026-105793?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
