CVE-2026-105793

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO_MCP_API_KEY, adb on the host, and a reachable authorized device, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-06: 210-06
Referenced assets2 URLs
Full discourse2 posts
  • VulnTracker@vuln_tracker

    Two Microsoft flaws, two broken checks. CVE-2026-105794 (MsQuic): spoofed servers pass TLS hostname checks. CVE-2026-105793 (UFO): a valid API key runs Android shell commands. VulnTracker recommends updating MsQuic to 2.6.1 and UFO to 3.0.9. #Microsoft #MsQuic https://t.co/3uAMxzLSvd

    20042167
    803 followersView on X
  • VulnTracker@vuln_tracker

    Details: https://vulntracker.io/cves/CVE-2026-105794 https://vulntracker.io/cves/CVE-2026-105793

    0000049
    803 followersView on X

Explore more