CVE-2026-46402
HIGHMicrosoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directory
Title source: cnaDescription
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause UFO to create log directories and log files outside the intended logs/ directory.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/microsoft/UFO/security/advisories/GHSA-whcg-fgpx-76f2
Scores
CVSS v3
8.1
EPSS
0.0067
EPSS Percentile
47.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
CWE-73
Status
published
Products (1)
microsoft/UFO
3.0.1-4-ge2626659
Published
May 27, 2026
Tracked Since
May 28, 2026