CVE-2026-105793 | Microsoft UFO up to 3.0.8 Mobile MCP Server mobile_mcp_server.py press_key key_code improper authorization

SecurityVulns

A vulnerability marked as critical has been reported in Microsoft UFO up to 3.0.8. The affected element is the function press_key of the file ufo/client/mcp/http_servers/mobile_mcp_server.py of the component Mobile MCP Server. The manipulation of the argument key_code leads to improper authorization.

This vulnerability is traded as CVE-2026-105793. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More