Junglewise Threat Intelligence

CVE-2026-41450: UAC Unix-like Artifacts Collector command injection in eval

CVE-2026-41450 · Severity: high · CVSS 7.8 · Published 2026-08-21

Executive brief

UAC (Unix-like Artifacts Collector) is a forensic tool used to collect system artifacts and logs on Unix-like systems for investigation and analysis. Versions before 3.3.0 contain a command injection vulnerability where untrusted input in filenames and artifact definitions is unsafely substituted into shell commands and executed, allowing an attacker to run arbitrary commands on the analyst's computer.

Technical details

The vulnerability is a command injection flaw in the _command_collector function where runtime placeholders (%user%, %user_home%, %line%) are substituted directly into command strings via sed without proper escaping before being evaluated with eval. An attacker can craft malicious filenames or artifact definitions containing shell metacharacters (semicolons, backticks, command substitution syntax) to break out of the intended command context and execute arbitrary shell commands. The vulnerability requires no authentication but depends on the analyst processing attacker-controlled input through the tool. The fix, merged in March 2026, escapes these placeholders according to shell context before they reach eval.

Affected products

  • tclahr UAC (Unix-like Artifacts Collector) prior to 3.3.0

Timeline

  • 2026-08-21: disclosed
  • 2026-03-28: patched: Fix merged in commit 2cc367d8ead388f05abd3cfb8af537788a124e72

References

Related threats