CVE-2026-46402

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause UFO to create log directories and log files outside the intended logs/ directory.
Configurations

No configuration.

History

30 May 2026, 02:16

Type Values Removed Values Added
References () https://github.com/microsoft/UFO/security/advisories/GHSA-whcg-fgpx-76f2 - () https://github.com/microsoft/UFO/security/advisories/GHSA-whcg-fgpx-76f2 -

27 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 23:16

Updated : 2026-05-30 02:16


NVD link : CVE-2026-46402

Mitre link : CVE-2026-46402

CVE.ORG link : CVE-2026-46402


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path