CWE-426: Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
286 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-49457 — Zoom Clients for Windows - Untrusted Search Path
- CVE-2025-65078 — Untrusted search path vulnerability in Embedded Solutions Framework
- CVE-2024-58250 — The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
- CVE-2025-31480 — aiven-extras allows PostgreSQL Privilege Escalation through format function
- CVE-2025-23266 — NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
- CVE-2026-29089 — TimescaleDB uses untrusted search path during extension upgrade
- CVE-2024-32019 — ndsudo: local privilege escalation via untrusted search path
- CVE-2026-23512 — SumatraPDF has an Untrusted Search Path in sumatrapdf/src/AppTools.cpp
- CVE-2025-4971 — Broadcom Automic Automation Agent Unix privilege escalation
- CVE-2025-2501 — An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate pr
- CVE-2025-12793 — An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap
- CVE-2025-0707 — Rise Group Rise Mode Temp CPU Startup CRYPTBASE.dll untrusted search path
- CVE-2024-9325 — Intelbras InControl incontrol-service-watchdog.exe unquoted search path
- CVE-2025-0141 — GlobalProtect App: Privilege Escalation (PE) Vulnerability
- CVE-2024-12168 — DLL Hijacking in Yandex Telemost
- CVE-2024-24810 — WiX is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
- CVE-2026-78155 — Untrusted Search Path in StackGres
- CVE-2026-44477 — CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
- CVE-2026-55769 — CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path`
- CVE-2026-33156 — DLL Sideloading in ScreenToGif
Recently published
- CVE-2026-80159 — Acrobat Reader | Untrusted Search Path (CWE-426)
- CVE-2026-81192 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
- CVE-2026-78574 — Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
- CVE-2026-84226 — OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform
- CVE-2026-82862 — Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files
- CVE-2026-81697 — openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration
- CVE-2026-75768 — Substance3D - Painter | Untrusted Search Path (CWE-426)
- CVE-2026-78680 — NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary
- CVE-2026-78155 — Untrusted Search Path in StackGres
- CVE-2026-55769 — CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path`
- CVE-2026-16869 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-74872 — openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool
- CVE-2026-16674 — IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty
- CVE-2026-14875 — IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
- CVE-2026-14673 — PostgreSQL amcheck does not clear untrusted search path
- CVE-2026-0299 — GlobalProtect App: Local Privilege Escalation Vulnerabilities
- CVE-2026-32791 — Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring
- CVE-2026-20799 — Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Ring 3: User Applicatio
- CVE-2026-55522 — PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
- CVE-2026-41447 — FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path