Sceawere

Vulnerability Detail

CVE-2026-105793UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft UFO Command Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
10h ago
Vendor
microsoft
Product
UFO
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO_MCP_API_KEY, adb on the host, and a reachable authorized device, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.9.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-06T15:17:16.123Z",
  "pubdate": "2026-10-06T15:17:16.123Z",
  "executiveSummary": "Microsoft UFO versions prior to 3.0.9 are susceptible to a command injection vulnerability within the mobile MCP server component.\nThe vulnerability originates from improper sanitization of user-supplied input passed to the 'adb shell' command, allowing an authenticated attacker to execute arbitrary commands on a connected Android device.\nThe impact is limited to the privileges of the Android shell user on the target device, but does not extend to the host operating system or elevated root permissions on the Android device.\nExploitation requires an attacker to possess a valid 'UFO_MCP_API_KEY' for the Mobile MCP interface, access to the 'adb' binary on the host environment, and an authorized, reachable Android device.\nThis flaw represents a critical risk for deployments where the UFO framework manages multiple mobile devices, as it allows for unauthorized interaction and potentially malicious command execution within the context of the mobile environment.",
  "technicalDetails": "The vulnerability resides in 'ufo/client/mcp/http_servers/mobile_mcp_server.py', specifically within the 'press_key' tool implementation.\nThe root cause of this security defect is the unsanitized concatenation of the 'key_code' parameter into an 'adb shell input keyevent' command string.\nBecause the 'adb' client processes and joins these arguments before passing them to the remote Android shell for parsing, the lack of input validation allows an attacker to inject shell metacharacters.\nAn authenticated attacker possessing a valid 'UFO_MCP_API_KEY' can craft a malicious 'key_code' payload containing shell command separators (e.g., semicolons, pipes, or logical operators). When the 'press_key' function executes, the remote Android shell interprets the injected sequences as distinct commands.\nThe attack flow proceeds as follows: First, the attacker makes a request to the Mobile MCP server with a crafted payload in the 'key_code' field. Second, the server invokes the 'adb shell' command, inadvertently including the malicious shell instructions. Third, the Android device receives and executes the full string via its command-line interface. Finally, the injected commands execute with the permissions of the Android shell user account.\nThis vulnerability is restricted by the execution context of the Android shell user. It does not facilitate privilege escalation to root, nor does it provide a vector for command execution on the host machine running the UFO framework. However, it permits full manipulation of the connected device within the scope of the shell user, such as file exfiltration, modification of system settings, or triggering additional device-level actions.\nThis issue is identified in versions prior to 3.0.9. Successful exploitation is contingent upon network accessibility to the UFO service, the availability of the 'adb' binary on the host environment, and successful authentication via the API key."
}
CVE-2026-105793: Microsoft UFO Command Injection Vulnerability (CRITICAL Severity, CVSS: 9.1) | Sceawere