Command Injection Vulnerability in UAC by TCLahr
CVE-2026-41449

8.5HIGH

Key Information:

Vendor

Tclahr

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-41449?

The UAC (Unix-like Artifacts Collector) software prior to version 3.3.0 is vulnerable to a command injection flaw residing in the _run_command function. This vulnerability stems from the inadequate handling of untrusted data sources such as usernames, process names, or filenames, which can be exploited by attackers injecting shell metacharacters. By carefully crafting inputs or manipulating artifact definitions, an attacker can execute arbitrary commands on the host machine during evidence processing, potentially leading to unauthorized remote access and further exploitation.

Affected Version(s)

uac 0 < 3.3.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mobasi Security Team
.