CWE-426— Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.— MITRE CWE catalog
751 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-426page 1 of 16
- CVE-2022-23748CRITICALCVSS 7.8EG 9.0⚠ KEV2022-11-17
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate e…
- CVE-2022-22047CRITICALCVSS 7.8EG 9.0⚠ KEV2022-07-12
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2012-1854CRITICALCVSS 7.8EG 9.0⚠ KEV2012-07-10
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users…
- CVE-2026-78155CRITICALCVSS 9.9EG 9.92026-08-23
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
- CVE-2026-44477CRITICALCVSS 9.9EG 9.92026-05-28
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres superuser via the pod-local …
- CVE-2026-74872CRITICALCVSS 9.8EG 9.82026-08-17
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .s…
- CVE-2026-45772CRITICALCVSS 9.8EG 9.82026-05-15
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn confi…
- CVE-2025-26155CRITICALCVSS 9.8EG 9.82025-11-26
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
- CVE-2024-53866CRITICALCVSS 9.8EG 9.82024-12-10
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and install…
- CVE-2024-35260CRITICALCVSS 9.8EG 9.82024-06-27
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
- CVE-2024-38462CRITICALCVSS 9.8EG 9.82024-06-16
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.
- CVE-2023-30330CRITICALCVSS 9.8EG 9.82023-05-12
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
- CVE-2022-24826CRITICALCVSS 9.8EG 9.82022-04-20
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code.…
- CVE-2022-26184CRITICALCVSS 9.8EG 9.82022-03-21
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs …
- CVE-2011-4125CRITICALCVSS 9.8EG 9.82021-10-27
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
- CVE-2020-15801CRITICALCVSS 9.8EG 9.82020-07-17
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
- CVE-2018-19486CRITICALCVSS 9.8EG 9.82018-11-23
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from exe…
- CVE-2017-12414CRITICALCVSS 9.8EG 9.82017-08-03
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.
- CVE-2017-2225CRITICALCVSS 9.8EG 9.82017-07-07
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVE-2025-4802CRITICALCVSS 7.8EG 9.82025-05-16
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including inte…
- CVE-2022-3734CRITICALCVSS 6.3EG 9.82022-10-28
A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The atta…
- CVE-2025-49457CRITICALCVSS 9.6EG 9.62025-08-12
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
- CVE-2026-55769CRITICALCVSS 9.4EG 9.42026-08-20
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/manageme…
- CVE-2025-65078CRITICALCVSS 9.3EG 9.32026-02-03
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
- CVE-2024-58250CRITICALCVSS 9.3EG 9.32025-04-22
The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
- CVE-2022-21817CRITICALCVSS 9.3EG 9.32022-02-02
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resour…
- CVE-2015-0096HIGHCVSS v2 9.3EG 9.32015-03-11
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows loc…
- CVE-2011-5158HIGHCVSS v2 9.3EG 9.32012-09-07
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvIn…
- CVE-2012-2040HIGHCVSS v2 9.3EG 9.32012-06-09
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x…
- CVE-2011-2019HIGHCVSS v2 9.3EG 9.32011-12-14
Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstr…
- CVE-2011-3691HIGHCVSS v2 9.3EG 9.32011-09-27
Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.
- CVE-2010-4833HIGHCVSS v2 9.3EG 9.32011-09-06
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than C…
- CVE-2025-31480CRITICALCVSS 9.1EG 9.12025-04-04
aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being …
- CVE-2026-45721CRITICALCVSS 9.0EG 9.02026-05-19
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured ser…
- CVE-2025-23266CRITICALCVSS 9.0EG 9.02025-07-17
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might …
- CVE-2026-59265HIGHCVSS 8.8EG 8.82026-10-02
A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in…
- CVE-2026-16674HIGHCVSS 8.8EG 8.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.
- CVE-2026-63093HIGHCVSS 8.8EG 8.82026-07-17
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and o…
- CVE-2026-53819HIGHCVSS 8.8EG 8.82026-06-11
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute…
- CVE-2026-29089HIGHCVSS 8.8EG 8.82026-03-06
TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqualified database objects (tables, functio…
- CVE-2026-24070HIGHCVSS 8.8EG 8.82026-02-02
During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permission…
- CVE-2024-44103HIGHCVSS 8.8EG 8.82024-09-10
DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
- CVE-2024-6975HIGHCVSS 8.8EG 8.82024-07-31
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.
- CVE-2024-6974HIGHCVSS 8.8EG 8.82024-07-31
Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.
- CVE-2024-32019HIGHCVSS 8.8EG 8.82024-04-12
Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a…
- CVE-2024-26198HIGHCVSS 8.8EG 8.82024-03-12
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2024-21435HIGHCVSS 8.8EG 8.82024-03-12
Windows OLE Remote Code Execution Vulnerability
- CVE-2023-43586HIGHCVSS 8.8EG 8.82023-12-13
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
- CVE-2022-4883HIGHCVSS 8.8EG 8.82023-02-07
A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to compress and uncompress files, relying on the PATH environment variable to find these programs, which could allow a malicio…
- CVE-2022-38060HIGHCVSS 8.8EG 8.82022-12-21
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
Map vulnerabilities like CWE-426 to your infrastructure
EchelonGraph correlates every CVE — across CWE-426 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →