VYPR
High severity7.8NVD Advisory· Published Apr 8, 2026· Updated Jul 24, 2026

CVE-2026-40032

CVE-2026-40032

Description

UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution pipeline where the _run_command() function passes constructed command strings directly to eval without proper sanitization. Attackers can inject shell metacharacters or command substitutions through attacker-controlled inputs including %line% values from foreach iterators and %user% / %user_home% values derived from system files to achieve arbitrary command execution with the privileges of the UAC process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Tclahr/Uacreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <3.3.0-rc1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.