CVE-2026-105792
Deferred Deferred - Pending Action

Microsoft UFO Session Lock Denial of Service

Vulnerability report for CVE-2026-105792, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager.py, which acquires a non-reentrant lock and then calls SessionManager.get_result() to acquire the same lock again when the task name maps to a session. An authenticated caller who knows or creates a mapped task name can therefore block the request indefinitely, and in the default single-process server configuration the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. Unknown task names do not reach the nested call and are not affected. This issue is fixed in version 3.0.9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft UFO < 3.0.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-833 The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service vulnerability in Microsoft UFO versions before 3.0.9. An authenticated attacker can exploit it by knowing or creating a specific task name that triggers a nested lock acquisition in the session manager. This blocks the event-loop thread indefinitely, preventing other HTTP, WebSocket, and background tasks from functioning.

Detection Guidance

Check the version of Microsoft UFO installed on your system. If it is below 3.0.9, the vulnerability is likely present. Run: ufo --version or check the package version in your environment.

Impact Analysis

If you use Microsoft UFO before version 3.0.9, an attacker could disrupt your automation framework by making it unresponsive. This could halt critical workflows, prevent device management, and block other users from accessing the system.

Mitigation Strategies

Upgrade Microsoft UFO to version 3.0.9 or later immediately. This fixes the issue by preventing the deadlock in the session manager. Verify the upgrade with: ufo --version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105792. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart