CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privi
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res
During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe
TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbit
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted s
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result i
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability wh
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow at
Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow att
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex
PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through a
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL w
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitra
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious bi
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a c
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows
OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowl
OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback th
ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the
A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to e
Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user t
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege esc
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA
FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly s
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygrap
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code executio
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc
Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of
Frequently Asked Questions
What is CWE-426?
CWE-426 (CWE-426) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-426?
There are 97 CVE records associated with CWE-426 in our database. Of these, 5 are critical severity, 68 are high severity, and 11 are medium severity.
How can I protect against CWE-426 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-426 using AI-powered security agents.
Detect CWE-426 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-426 vulnerabilities across your infrastructure.
Get Started