PT-2026-31469 · Tclahr · Uac

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-40032

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution pipeline where the run command() function passes constructed command strings directly to eval without proper sanitization. Attackers can inject shell metacharacters or command substitutions through attacker-controlled inputs including %line% values from foreach iterators and %user% / %user home% values derived from system files to achieve arbitrary command execution with the privileges of the UAC process.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-40032

Affected Products

Uac