Medium severity6.5NVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
CVE-2026-55440
CVE-2026-55440
Description
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned attacker-chosen session_id such as constellation_task_id = f"{task_name}@{task_id}" and deny the legitimate owner or exhaust memory with phantom sessions. This issue is fixed in version 3.0.7.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.