Vulnerability
Published 2026-08-31
Verified 2026-09-19

Microsoft UFO Mobile MCP unauthenticated Android control (CVE-2026-73296)

Cyber Security News (31 August 2026) reports CVE-2026-73296 in Microsoft's open-source UFO automation framework: Mobile Model Context Protocol servers (data collection on TCP 8020, action on TCP 8021) accepted MCP requests without authentication when bound for remote access (0.0.0.0). Default bind is localhost. An exposed action server can tap, swipe, type, launch apps and drive a connected Android device or emulator over ADB; the data server can return screenshots and UI hierarchy. CSN cites GitHub advisory GHSA-24fq-m9rr-g3mm (CWE-306 / CWE-862) and a CVSS of 9.4; that GitHub advisory URL returned 404 this pass, so the score is not confirmed from GitHub and is not copied into the CVSS field. Microsoft's fix is UFO 3.0.8, which adds mandatory bearer-token auth via UFO_MCP_API_KEY and is described as refusing startup if the key is missing. Until patched, keep Mobile MCP on localhost and block 8020/8021. Wire source until the GHSA page is readable.

Product
Microsoft UFO (Mobile MCP / Android via ADB)
Versions
Before 3.0.8, when Mobile MCP is exposed remotely
Exploited in Australia?
unknown
Patch to
UFO 3.0.8 or later; UFO_MCP_API_KEY required

Primary: Cyber Security News (31 Aug 2026) · Vendor: GHSA-24fq-m9rr-g3mm (404 this pass) · CVE: CVE-2026-73296

vulnerabilities ai