CVE-2026-73296
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, createmobiledatacollectionserver and createmobileactionserver in ufo/client/mcp/httpservers/mobilemcpserver.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capturescreenshot, getuitree, tap, swipe, typetext, launchapp, presskey, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/microsoft/UFO/releases/tag/v3.0.8, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73296.json, https://github.com/microsoft/UFO/security/advisories/GHSA-24fq-m9rr-g3mm, https://nvd.nist.gov/vuln/detail/CVE-2026-73296, https://github.com/microsoft/UFO/commit/e562d10060b077dedae93e0fd58c1ee379558962