CVE-2026-54568
MEDIUMMicrosoft UFO 3.0.0 to < 3.0.6 - Device Info Authorization Bypass
Title source: manualDescription
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through ufo/server/ws/handler.py, because handle_device_info_request and get_device_info did not enforce the constellation-only role or object-level authorization boundary. This issue is fixed in version 3.0.6.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/microsoft/UFO/security/advisories/GHSA-hc27-j4p9-qm2x
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/UFO/commit/2558da4e7dd05096aa6b489eca64efed96126713
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/UFO/releases/tag/3.0.6
Scores
CVSS v3
4.3
EPSS
0.0054
EPSS Percentile
42.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
CWE-862
Status
published
Products (1)
microsoft/UFO
>= 3.0.0, < 3.0.6
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026