CVE-2026-41451: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in tclahr uac
Description
CVE-2026-41451 is a command injection vulnerability in tclahr's UAC (Unix-like Artifacts Collector) versions prior to 3.3.0. The flaw exists in the parse_artifact.sh script where usernames and home directory paths from /etc/passwd are directly substituted into commands without proper escaping before being executed via eval. This allows attackers to inject shell metacharacters through crafted /etc/passwd entries, potentially leading to arbitrary command execution on the analyst's host system.
CVSS v4.0
Score 8.5high
Affected software
tclahr
uac
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from improper neutralization of special elements in OS commands within the user substitution logic of parse_artifact.sh in UAC versions before 3.3.0. Specifically, usernames and home directories extracted from /etc/passwd are inserted into command strings without escaping, and these commands are executed using eval. An attacker who can influence /etc/passwd entries can inject shell metacharacters such as command substitution syntax or semicolons, enabling execution of arbitrary commands on the host system running the UAC tool.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary commands on the analyst's host system with the privileges of the user running UAC. This can lead to system compromise, data exposure, or further attacks. The vulnerability requires the attacker to control or influence /etc/passwd entries, which may limit the attack vector depending on system configuration.
Mitigation Recommendations
A fix is available in UAC version 3.3.0 and later. Users should upgrade to version 3.3.0 or newer to remediate this vulnerability. Until then, avoid running UAC on systems where /etc/passwd entries may be untrusted or manipulated. No vendor advisory content was provided to indicate alternative mitigations or temporary fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-04-20T16:07:47.309Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a88906bacd9273b497ffd5f
Added to database: 08/21/2026, 17:52:43 UTC
Last enriched: 09/10/2026, 17:36:05 UTC
Last updated: 10/05/2026, 18:48:19 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.