Report: CVE-2026-46414 - Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking - Guide

Report: CVE-2026-46414 - Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking - Guide

CVE ID :CVE-2026-46414 Published : May 27, 2026, 11:16 p.m. | 14 minutes ago Description :Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK message claiming client_type=

CVE Details

Published
May 27, 2026
Affected Product: Microsoft UFO