Command Injection Vulnerability in UAC by TCLahr
CVE-2026-41449
8.5HIGH
What is CVE-2026-41449?
The UAC (Unix-like Artifacts Collector) software prior to version 3.3.0 is vulnerable to a command injection flaw residing in the _run_command function. This vulnerability stems from the inadequate handling of untrusted data sources such as usernames, process names, or filenames, which can be exploited by attackers injecting shell metacharacters. By carefully crafting inputs or manipulating artifact definitions, an attacker can execute arbitrary commands on the host machine during evidence processing, potentially leading to unauthorized remote access and further exploitation.
Affected Version(s)
uac 0 < 3.3.0
