Skip to main content

Threats Tagged 'cwe-426'

View all threats tagged with 'cwe-426'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-426

Threats Tagged 'cwe-426'

Click on any threat for detailed analysis and mitigation recommendations

0

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical URL string pass the file-access check while git resolved it outside the sandbox. A subsequent fetch or pull read a git repository outside N8N_RESTRICT_FILE_ACCESS_TO and merged its objects into the user's own repository, where their contents could be read back. The issue is fixed in n8n 1.123.76, 2.37.7, and 2.38.2, which resolve the remote reference from the directory git actually operates in before applying the sandbox check. As a workaround, the Git node can be disabled by adding n8n-nodes-base.git to NODES_EXCLUDE.

Join the discussion

CVE-2026-0307 is a local privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app for Windows, macOS, and Linux. It allows a local non-administrative user to escalate privileges to SYSTEM on Windows or root on macOS and Linux by exploiting an untrusted search path issue. The vulnerability does not affect the GlobalProtect app on iOS, Android, or ChromeOS. The CVSS 4.0 score is 5.9, indicating medium severity.

Join the discussion

Adobe Acrobat contains an Untrusted Search Path vulnerability (CWE-426) that could allow an attacker with high privileges to escalate their access. Exploitation requires user interaction, specifically opening a malicious file. The vulnerability affects versions up to 26.002.21900 and 24.001.30383. The CVSS score is 4.0, indicating medium severity.

Join the discussion

An untrusted search path vulnerability exists in the OpenTelemetry.Resources.Host NuGet package for macOS hosts prior to version 1.16.0-beta.2. The vulnerability arises because the host.id resource attribute detector launches the 'sh' and 'ioreg' executables by bare name, relying on the PATH environment variable for resolution. A local attacker with lower privileges who can manipulate the PATH or write to a directory earlier in the PATH can execute arbitrary binaries in the application's security context, leading to local code execution or privilege escalation. This issue affects only macOS hosts; Linux and Windows are not impacted. The vulnerability is patched in version 1.16.0-beta.2. No known workarounds are available.

Join the discussion

Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Join the discussion

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

Join the discussion

Adobe Substance3D - Painter has an Untrusted Search Path vulnerability (CWE-426) that could allow an attacker to execute arbitrary code with the privileges of the current user. Exploitation requires user interaction, specifically opening a malicious file. The vulnerability has a high severity score of 7.8. No patch or official remediation has been confirmed yet.

Join the discussion

CVE-2026-78155 is a critical privilege escalation vulnerability in the StackGres operator by OnGres. It involves an untrusted search path issue (CWE-426) that allows a low-privilege tenant who owns a database to escalate their privileges to administrator level. The vulnerability has a high CVSS score of 9.9, indicating severe impact on confidentiality, integrity, and availability. No patch or official remediation information is currently available. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-16869 is a high severity vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. It involves an untrusted search path issue where improperly scrubbed environment variables could allow a local attacker to execute arbitrary code. The vulnerability has a CVSS 3.1 score of 7.8, indicating significant confidentiality, integrity, and availability impact. No vendor patch or remediation information is currently provided.

Join the discussion

A vulnerability in PostgreSQL's amcheck extension allows a user with EXECUTE privilege on the amcheck function to execute arbitrary functions as owners of expression indexes by manipulating the search path. This affects PostgreSQL major versions 14, 15, 16, and 18 in specific minor versions before 14.24, 15.19, 16.15, and 18.5 respectively. PostgreSQL 17 is not affected. The issue arises from not clearing an untrusted search path before executing the function.

Join the discussion

Showing 1 to 10 of 83 results

Filters:Tag: cwe-426
Page 1 of 9
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses