CWE-426
High likelihoodUntrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
657 vulnerabilities with CWE-426
CVE-2026-48395
HIGH
Adobe Bridge - Bridge | Untrusted Search Path (CWE-426)
CVSS 8.6
CVE-2026-48391
HIGH
Adobe Bridge - Bridge | Untrusted Search Path (CWE-426)
CVSS 8.2
CVE-2026-63093
HIGH
Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
CVSS 8.8
CVE-2026-48287
HIGH
CAI Content Credentials | Untrusted Search Path (CWE-426)
CVSS 7.4
CVE-2026-48275
HIGH
Adobe Illustrator Desktop 2026 - Illustrator | Untrusted Search Path (CWE-426)
CVSS 8.6
CVE-2026-48346
HIGH
Adobe Animate 2023 - Animate | Untrusted Search Path (CWE-426)
CVSS 7.9
CVE-2026-57097
MEDIUM
Microsoft XML Security Feature Bypass Vulnerability
CVSS 6.4
CVE-2026-15515
HIGH
Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
CVSS 7.0
CVE-2026-49145
HIGH
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc
CVSS 7.5
CVE-2026-6901
HIGH
B&R Industrial Automation APROL - Untrusted Search Path
CVSS 7.7
CVE-2026-57919
HIGH
Matrix42 Empirum < 25.5 and 26.x < 26.2 - Privilege Escalation via Named Pipe IPC
CVSS 7.8
CVE-2026-46710
HIGH
Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path
CVSS 7.8
CVE-2026-45792
MEDIUM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
CVSS 5.5
CVE-2026-53865
HIGH
OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH
CVSS 7.1
CVE-2026-53858
HIGH
OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment Variable
CVSS 7.1
CVE-2026-53846
HIGH
OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpath
CVSS 7.1
CVE-2026-53842
HIGH
OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment Variable
CVSS 7.1
CVE-2026-54055
MEDIUM
Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol
CVSS 5.0
CVE-2026-53819
HIGH
OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env Override
CVSS 8.8
CVE-2026-48565
HIGH
Windows Narrator Braille Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-47648
HIGH
Microsoft Windows 10 Version 1607 - Windows Storage Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-24064
HIGH
Local Privilege Escalation via Dynamic Library Injection in Waves Central for macOS
CVSS 7.8
CVE-2026-11401
HIGH
Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL
CVSS 8.0
CVE-2026-11400
HIGH
Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL
CVSS 8.0
CVE-2026-44477
CRITICAL
CloudNativePG Metrics Exporter - PostgreSQL Superuser Privilege Escalation
CVSS 9.9
Details
Vulnerabilities
657
Exploit Likelihood
High