CVE Explorer
CVE-2026-46414
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK message claiming client_type="constellation" and target_id=<victim-device-id>. The server trusts the role and target values from the wire message rather than enforcing the role registered for that WebSock
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-290","description":"CWE-290: Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"UFO","vendor":"microsoft","versions":[{"status":"affected","version":"3.0.1-4-ge2626659"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-290","description":"CWE-290: Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/microsoft/UFO/security/advisories/GHSA-qgx6-cvhg-jw7p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-qgx6-cvhg-jw7p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/microsoft/UFO/security/advisories/GHSA-qgx6-cvhg-jw7p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cc130c0a7edd60ecd2a2723c9984e27f87b71082b209b4a8bb5b45f9120c3227 · sha256:112b88875bda7efc… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.