External risk intelligence

Microsoft UFO Mobile MCP Server Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105793

The vulnerability resides in a mobile MCP server tool used for automation and requires a valid API key, ADB configuration on the host, and a locally connected authorized device. While network-reachable in some automation environments, it is typically an internal tool for developer or device-management workflows rather than a public-facing service.

OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the Microsoft UFO open-source automation framework, specifically its mobile command and control protocol server. An authenticated user could potentially execute unintended commands on a connected Android device. While the framework is designed for automation, the risk is primarily within environments where this tool is deployed and accessible.

  • Allows unintended commands on connected devices.
  • Matters for secure automation and connected device management.
  • Confirm relevance and exposure within your automation environments.

Attack Path

How an attacker could exploit the issue

An attacker with valid credentials and access to the Mobile MCP server could trick the `press_key` tool into executing arbitrary commands on a connected Android device. This is possible because the tool passes a free-form parameter to a command-line utility that reinterprets it, allowing the attacker to break out and run their own commands as the Android shell user. This could lead to limited command execution on the device.

  • Authenticated user access required.
  • Input to `press_key` tool is mishandled.
  • Limited command execution on device.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory's conditions, an authenticated caller using a valid API key could execute arbitrary commands as the Android shell user on a connected device. This does not grant host operating system execution or Android root access.

  • Affected asset: Connected Android device.
  • Exposure: Commands injected via press_key tool.
  • Consequence: Unauthorized Android shell-user actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for managing the Microsoft UFO framework, potentially including platform or automation engineering teams, should lead the response. The initial step is to identify all instances of the affected UFO version, confirm their reachability and criticality, and locate the accountable owner for each deployment. This will inform a risk-based remediation plan.

  • Platform or automation teams own the issue.
  • Verify UFO instances and their reachability.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft UFO?

Microsoft UFO is an open-source automation framework. Developers use it to manage, control, and orchestrate tasks across various devices and platforms. It specifically includes tools for handling interactions with connected mobile devices, such as the Mobile MCP server component involved in this vulnerability.

How does CVE-2026-105793 cause a security weakness?

This issue is an OS Command Injection, classified as CWE-78. It occurs when a software tool improperly handles user input before passing it to a system command. In this case, the `press_key` tool takes a key-code parameter and fails to properly sanitize it, allowing an attacker to insert extra commands that the Android shell then executes.

Do I need an Android device attached to trigger this bug?

Yes. Beyond having a valid API key, the attacker must have an authorized Android device actively connected to the host and reachable by the UFO server. Simply accessing the server without these specific prerequisites, such as the ADB configuration and a physical or emulated device link, will not result in command execution.

Is my environment at risk if the UFO server is internal?

Halo Surface Signal indicates that while this is technically a network-reachable issue, it is unlikely to be a high-risk concern for most. The vulnerability typically resides in internal developer or device-management workflows. It is most relevant in environments where you have explicitly connected authorized mobile devices for automation purposes.

When should I update my UFO framework?

You should prioritize updates if you manage instances of the Microsoft UFO framework earlier than version 3.0.9. Your first step is to locate all active deployments, verify which ones have access to connected mobile devices, and coordinate with your automation team to apply the update provided by the maintainers.

References