CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

639 vulnerabilities with CWE-426
CVE-2026-54055 MEDIUM
Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol
CVSS 5.0
CVE-2026-53819 HIGH
OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env Override
CVSS 8.8
CVE-2026-48565 HIGH
Windows Narrator Braille Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-47648 HIGH
Microsoft Windows 10 Version 1607 - Windows Storage Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-24064 HIGH
Local Privilege Escalation via Dynamic Library Injection in Waves Central for macOS
CVSS 7.8
CVE-2026-11401 HIGH
Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL
CVSS 8.0
CVE-2026-11400 HIGH
Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL
CVSS 8.0
CVE-2026-44477 CRITICAL
CloudNativePG Metrics Exporter - PostgreSQL Superuser Privilege Escalation
CVSS 9.9
CVE-2026-45721 CRITICAL
Algernon: handler.lua discovery walks parent directories above the server root
CVSS 9.0
CVE-2026-45772 CRITICAL
Turborepo: Unexpected local code execution during Yarn Berry detection
CVSS 9.8
CVE-2026-30906 HIGH
Zoom Rooms < 7.0.0 - Authenticated Privilege Escalation via Untrusted Search Path
CVSS 7.8
CVE-2026-0251 MEDIUM
GlobalProtect App: Local Privilege Escalation Vulnerabilities
CVE-2026-42830 MEDIUM
Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVSS 6.5
CVE-2026-7309 MEDIUM
Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection
CVSS 4.3
CVE-2026-35368 HIGH
uutils coreutils chroot Local Privilege Escalation and chroot Escape in via Name Service Switch (NSS) Injection
CVSS 7.8
CVE-2026-35603 HIGH
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
CVSS 7.3
CVE-2026-6421 HIGH
Mobatek MobaXterm Home Edition msimg32.dll uncontrolled search path
CVSS 7.0
CVE-2026-40947 LOW
Yubico libfido2 <1.17.0 - DLL Hijacking
CVSS 2.9
CVE-2026-27290 HIGH
Adobe Framemaker | Untrusted Search Path (CWE-426)
CVSS 8.6
CVE-2026-40287 HIGH
PraisonAI has RCE via Automatic tools.py Import
CVSS 8.4
CVE-2026-40156 HIGH
PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVSS 7.8
CVE-2026-39883 HIGH
OpenTelemetry-Go 1.15.0-1.42.0 - BSD kenv PATH Hijacking
CVSS 7.0
CVE-2026-3780 HIGH
Foxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege Escalation
CVSS 7.3
CVE-2026-4962 HIGH
UltraVNC Service version.dll uncontrolled search path
CVSS 7.0
CVE-2026-4546 HIGH
Flos Freeware Notepad2 TextShaping.dll uncontrolled search path
CVSS 7.0
Details
Vulnerabilities 639
Exploit Likelihood High