CVE-2026-105789
Deferred Deferred - Pending Action

Microsoft UFO Command Injection Vulnerability

Vulnerability report for CVE-2026-105789, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft UFO < 3.0.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Microsoft UFO before 3.0.9 has a flaw in the execute_command tool where sort and uniq are treated as read-only but can be used with file-output options like sort -o or uniq's second operand. An authenticated user can exploit this to create or overwrite files writable by the UFO server process without using shell metacharacters. This can corrupt configuration or other data and disrupt the service but does not directly disclose files or enable arbitrary code execution.

Detection Guidance

This vulnerability can be detected by checking the version of Microsoft UFO installed on your system. If the version is below 3.0.9, the system is vulnerable. Use the command: ufo --version to check the installed version.

Impact Analysis

If you use Microsoft UFO versions before 3.0.9, an attacker with authentication could overwrite critical files like configurations, leading to service disruption or data corruption. This could cause downtime or require manual recovery of affected files.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized file modifications, potentially violating integrity requirements in GDPR or HIPAA. If configuration or data files are corrupted, it may affect audit trails or data integrity controls, though direct data disclosure is not part of this issue.

Mitigation Strategies

Immediately upgrade Microsoft UFO to version 3.0.9 or later to address the vulnerability. If upgrading is not possible, restrict access to the execute_command tool and monitor file writes in directories accessible by the UFO server process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105789. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart