Sceawere

Vulnerability Detail

CVE-2026-105788UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft UFO ADB Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
11h ago
Vendor
microsoft
Product
UFO
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.10, the type_text and launch_app tools in ufo/client/mcp/http_servers/mobile_mcp_server.py pass the authenticated caller-controlled text and package_name parameters into adb shell command argument positions without comprehensive validation. The adb client joins those arguments into a remote command string that the Android shell reparses, allowing shell metacharacters to execute additional commands on an authorized connected device as the Android shell user. Exploitation requires a valid Mobile MCP API key and a reachable device authorized for ADB, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.10.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T14:17:40.077Z",
  "pubdate": "2026-10-06T14:17:40.077Z",
  "executiveSummary": "Microsoft UFO contains a critical command injection vulnerability stemming from improper input validation within its Mobile MCP server components. Versions prior to 3.0.10 are susceptible to arbitrary shell command execution on connected Android devices.\nThe vulnerability originates in the 'type_text' and 'launch_app' tools, where user-supplied parameters are directly concatenated into 'adb shell' command strings without sanitization. This allows an authenticated attacker to inject shell metacharacters, effectively escaping intended command boundaries to execute unauthorized shell commands on the target Android device.\nWhile exploitation is restricted to the privileges of the Android shell user and requires a valid Mobile MCP API key alongside physical or network reachability to an ADB-authorized device, the flaw represents a significant security oversight in automated device management frameworks.\nThe impact is limited to the scope of the Android device shell and does not escalate to the host operating system or provide Android root access. However, attackers can leverage this to manipulate device state, exfiltrate application data, or perform unauthorized actions via the ADB bridge.\nUsers and administrators are strongly advised to update to version 3.0.10 or later to remediate this vulnerability.",
  "technicalDetails": "The vulnerability resides within 'ufo/client/mcp/http_servers/mobile_mcp_server.py'. The 'type_text' and 'launch_app' functions fail to adequately sanitize the 'text' and 'package_name' parameters before passing them to the underlying Android Debug Bridge (ADB) execution logic. Because the ADB client interprets these arguments by joining them into a single command string for the target Android shell, the lack of input validation allows for command injection via shell metacharacters.\nThe root cause is an insecure implementation of command construction where caller-controlled data is treated as trusted. When the 'adb shell' command is executed, the remote Android shell parses the command string in its entirety. An attacker providing a payload containing characters such as semicolons, backticks, or pipes can terminate the intended command and inject arbitrary sequences. For example, injecting '; <malicious_command>' allows for the execution of secondary instructions under the context of the Android shell user.\nThe exploitation flow proceeds as follows: 1) An attacker authenticates to the Mobile MCP API using a valid API key. 2) The attacker identifies a target Android device reachable via ADB and already in an authorized state. 3) The attacker triggers either the 'type_text' or 'launch_app' functions, crafting the input parameter to include shell injection sequences. 4) The 'mobile_mcp_server.py' component passes the malicious string directly to the system shell. 5) The Android OS executes the original intended command followed by the attacker's injected command payload.\nThis vulnerability is restricted by the existing security posture of the ADB bridge. It requires the device to be previously authorized to communicate with the host, ensuring that the attacker cannot bypass ADB authentication mechanisms. The impact is contained strictly within the Android subsystem; the vulnerability does not provide a path for lateral movement to the host machine running the UFO framework, nor does it provide inherent root privileges, as commands are executed with the permissions of the current Android shell user. However, for an automated framework, this allows for persistent manipulation of the device environment, which may be leveraged for further malicious activities on the mobile platform."
}
CVE-2026-105788: Microsoft UFO ADB Command Injection (HIGH Severity, CVSS: 8.8) | Sceawere