CVSS
9.4
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 12, 2026
Exploitability
No EPSS data available
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).