Description
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO_MCP_API_KEY, adb on the host, and a reachable authorized device, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.9.
Published: 2026-10-06
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Authenticated Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

Microsoft UFO’s press_key tool accepts an unvalidated key_code argument and forwards it to the adb shell. An attacker who authenticates with a valid UFO_MCP_API_KEY can inject additional commands, causing the Android shell user to execute arbitrary commands on a connected device. The flaw does not elevate privileges beyond the Android shell user or grant host‑OS access, but it still allows privileged operations on the device. The weakness is a classic shell injection (CWE‑78).

Affected Systems

Microsoft UFO is affected in all releases prior to version 3.0.9. Anyone using an older UFO build and exposing the Mobile MCP press_key endpoint, with an active UFO_MCP_API_KEY, could be impacted. The vulnerability is fixed in UFO v3.0.9 and later.

Risk and Exploitability

With a CVSS score of 9.1, this flaw poses a high risk. EPSS is not available, and it is not listed in the CISA KEV catalog. Exploitation requires that the attacker have a valid UFO_MCP_API_KEY, that the UFO host has adb installed, that a device is connected and reachable, and that the press_key endpoint is exposed. Once those conditions are met, the attacker can run commands as the Android shell user. The attack surface is therefore limited to devices configured for the UFO Mobile MCP API, but the impact on each device is significant, allowing control over installed applications, data, and device state.

Generated by OpenCVE AI on October 6, 2026 at 18:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to UFO version 3.0.9 or later where the press_key input is sanitized.
  • Restrict the UFO_MCP_API_KEY to a minimal set of trusted clients and rotate keys regularly.
  • If immediate upgrade is not possible, disable or restrict the press_key endpoint, limit network access to the Mobile MCP API, and ensure that only authorized IPs can reach it.

Generated by OpenCVE AI on October 6, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote command string that the Android shell reparses, allowing an authenticated Mobile MCP caller to execute additional commands as the Android shell user on an authorized connected device. Exploitation requires a valid UFO_MCP_API_KEY, adb on the host, and a reachable authorized device, and it does not establish host operating-system execution, Android root execution, or access beyond the Android shell-user privileges. This issue is fixed in version 3.0.9.
Title Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key`
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T15:01:03.322Z

Reserved: 2026-10-05T20:37:19.364Z

Link: CVE-2026-105793

cve-icon Vulnrichment

Updated: 2026-10-06T15:00:45.470Z

cve-icon NVD

Status : Deferred

Published: 2026-10-06T15:17:16.123

Modified: 2026-10-06T16:17:05.703

Link: CVE-2026-105793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')