CVE-2026-105790: Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinning via redirects

Published Oct 6, 2026
·
Updated

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinnedaddresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.

Affected Software

1 affected component
Microsoft UFO<3.0.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Microsoft UFO to a version that resolves this vulnerability.

    Fixed in 3.0.9

Event History

Oct 6, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs to be authenticated and able to register a Galaxy device through the /api/devices endpoint. They must control a WebSocket endpoint that is permitted by the initial address-pinning checks and can redirect the client to an internal host reachable by the UFO server.

2

Are default deployments affected?

The available information does not establish whether the vulnerable Galaxy device-registration workflow or its relevant WebSocket configuration is enabled by default. Exposure depends on authenticated access to /api/devices and the server being able to reach internal redirect targets.

3

What is the actual impact of a successful exploit?

The confirmed impact is that the server makes an internal TCP connection and sends a WebSocket handshake request to the redirected host. The issue does not confirm arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access.

4

What should teams do if they cannot upgrade immediately?

Restrict authenticated access to device registration and limit the UFO server's network reachability to internal systems that should not receive WebSocket connections. The issue is fixed in version 3.0.9.

5

How can teams identify potentially affected systems?

Systems running a version prior to 3.0.9 that allow authenticated Galaxy device registration through /api/devices are potentially affected. Review registration activity and outbound connections for WebSocket handshakes to unexpected internal destinations following connections to attacker-controlled endpoints.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203