CVE-2026-41451 | tclahr UAC up to 3.2.x User Substitution Logic parse_artifact.sh eval username/home command injection

SecurityVulns

A vulnerability described as problematic has been identified in tclahr UAC up to 3.2.x. This affects the function eval of the file parse_artifact.sh of the component User Substitution Logic. Such manipulation of the argument username/home leads to command injection.

This vulnerability is traded as CVE-2026-41451. An attack has to be approached locally. There is no exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More