VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (691)

page 5 of 35
  • CVE-2026-75768HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user…

  • CVE-2026-16869HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.

  • CVE-2026-0299HigAug 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with…

  • CVE-2026-56174HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

  • CVE-2026-41447HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious…

  • CVE-2026-48346HigJul 14, 2026
    risk 0.51cvss 7.9epss 0.00

    Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

  • CVE-2026-48565HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24064HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the…

  • CVE-2026-30906HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2026-0251HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands…

  • CVE-2026-35368HigApr 22, 2026
    risk 0.51cvss 7.8epss 0.00

    A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves the user specification via getpwnam() after entering the chroot but before dropping root privileges. On glibc-based systems, this can trigger the Name Service…

  • CVE-2026-33156HigMar 20, 2026
    risk 0.51cvss 7.8epss 0.00

    ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the…

  • CVE-2026-25190HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

  • CVE-2026-2998HigFeb 23, 2026
    risk 0.51cvss 7.8epss 0.00

    ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

  • CVE-2026-25880HigFeb 9, 2026
    risk 0.51cvss 7.8epss 0.00

    SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code…

  • CVE-2026-0662HigFeb 4, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.

  • CVE-2025-12793HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS'…

  • CVE-2025-67722HigDec 16, 2025
    risk 0.51cvss 7.8epss 0.00

    FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated…

  • CVE-2025-64785HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a…

  • CVE-2025-60718HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.