CVE-2026-105789 | Microsoft UFO up to 3.0.8 Linux MCP Server linux_mcp_server.py execute_command file inclusion (EUVD-2026-93406)
A vulnerability, which was classified as problematic, was found in Microsoft UFO up to 3.0.8. This affects the function execute_command of the file ufo/client/mcp/http_servers/linux_mcp_server.py of the component Linux MCP Server. Such manipulation of the argument command leads to file inclusion.
This vulnerability is referenced as CVE-2026-105789. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More