Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-426

MITRE ↗

CWE-426

5
CRITICAL
68
HIGH
11
MEDIUM
3
LOW
93 CVEs · Page 1/2
9.9
CVE-2026-44477

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and

9.9
CVE-2026-78155

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privi

9.8
CVE-2026-45772

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo

9.8
CVE-2026-74872

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa

9.0
CVE-2026-45721

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res

8.8
CVE-2026-24070

During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe

8.8
CVE-2026-29089

TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve

8.8
CVE-2026-53819

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env

8.8
CVE-2026-63093

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbit

8.8
CVE-2026-16674

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted s

8.6
CVE-2026-21280

Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result i

8.6
CVE-2026-23512

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability wh

8.6
CVE-2026-21333

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow at

8.6
CVE-2026-27290

Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow att

8.6
CVE-2026-48275

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c

8.6
CVE-2026-48395

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex

8.4
CVE-2026-40287

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through a

8.2
CVE-2026-48391

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex

8.0
CVE-2026-11400

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL

8.0
CVE-2026-11401

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL w

7.9
CVE-2026-48346

Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte

7.8
CVE-2025-12793

An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap

7.8
CVE-2026-0662

A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitra

7.8
CVE-2026-25880

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious bi

7.8
CVE-2026-2998

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a c

7.8
CVE-2026-25190

Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-32015

OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows

7.8
CVE-2026-32016

OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowl

7.8
CVE-2026-32032

OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback th

7.8
CVE-2026-33156

ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading

7.8
CVE-2026-40156

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the

7.8
CVE-2026-35368

A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves

7.8
CVE-2026-0251

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e

7.8
CVE-2026-30906

Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t

7.8
CVE-2026-24064

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC

7.8
CVE-2026-48565

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-46710

Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege esc

7.8
CVE-2026-57919

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA

7.8
CVE-2026-41447

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit

7.8
CVE-2026-55522

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p

7.8
CVE-2026-56174

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-16869

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly s

7.8
CVE-2026-78680

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygrap

7.8
CVE-2026-75768

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code executio

7.7
CVE-2026-6901

Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P

7.5
CVE-2026-49145

App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th

7.4
CVE-2026-48287

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut

7.3
CVE-2026-25926

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions

7.3
CVE-2026-3780

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc

7.3
CVE-2022-4987

Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of

Frequently Asked Questions

What is CWE-426?

CWE-426 (CWE-426) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-426?

There are 97 CVE records associated with CWE-426 in our database. Of these, 5 are critical severity, 68 are high severity, and 11 are medium severity.

How can I protect against CWE-426 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-426 using AI-powered security agents.

Detect CWE-426 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-426 vulnerabilities across your infrastructure.

Get Started