PT-2026-79408 · Uac · Uac

CVE-2026-41449

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
Description A command injection issue exists in the run command() function. This allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data, including usernames, process names, or filenames. Exploitation can occur through crafted evidence inputs, mounted images containing hostile filenames, or tampered artifact definitions, potentially leading to remote code execution on the analyst's host during evidence processing.
Recommendations Update to version 3.3.0 or later.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41449

Affected Products

Uac