PT-2026-79408 · Uac · Uac
CVE-2026-41449
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
Description
A command injection issue exists in the
run command() function. This allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data, including usernames, process names, or filenames. Exploitation can occur through crafted evidence inputs, mounted images containing hostile filenames, or tampered artifact definitions, potentially leading to remote code execution on the analyst's host during evidence processing.Recommendations
Update to version 3.3.0 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uac