Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-426'

View all threats tagged with 'cwe-426'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-426

Threats Tagged 'cwe-426'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-55522: CWE-94: Improper Control of Generation of Code ('Code Injection') in MervinPraison PraisonAICVE-2026-55522
0

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw importlib.util.spec_from_file_location() and spec.loader.exec_module() call, without honoring the PRAISONAI_ALLOW_TEMPLATE_TOOLS/PRAISONAI_ALLOW_LOCAL_TOOLS autoload opt-in gates or routing through the centralized safe loader that protects the other tools.py autoload paths. As a result, a workflow that includes an attacker-controlled local recipe directory executes arbitrary module-level Python code during include setup, before any child workflow parsing or model call, and the same sink is reachable through the higher-level praisonai.recipe.run() recipe API. An attacker who can cause a victim process to run a workflow or recipe that includes an untrusted local recipe achieves arbitrary Python code execution as the PraisonAI process user, a variant that bypasses the hardening applied to the previously disclosed automatic tools.py RCE advisory family. This issue has been fixed in version 4.6.58 of praisonai and 1.6.58 of praisonaiagents.

Join the discussion
CVE-2026-47211: CWE-426: Untrusted Search Path in Q00 ouroborosCVE-2026-47211
0

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover. The vulnerability stems from Ouroboros loading the .env file from the current working directory. Execution-affecting environment variables such as OUROBOROS_CLI_PATH, OPENCODE_CLI_PATH, and other backend selectors are accepted directly from this local .env. An attacker can include a malicious script in the repository and point the CLI path variable to it (e.g., OUROBOROS_CLI_PATH=./malicious_script.sh). When the user executes a command like ouroboros init or any command that instantiates the adapter, the malicious script is executed instead of the intended CLI. This issue has been fixed in version 0.39.0.

Join the discussion
CVE-2026-48395: Untrusted Search Path (CWE-426) in Adobe Adobe BridgeCVE-2026-48395
0

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Join the discussion
CVE-2026-48391: Untrusted Search Path (CWE-426) in Adobe Adobe BridgeCVE-2026-48391
0

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Join the discussion
CVE-2026-48287: Untrusted Search Path (CWE-426) in Adobe Content Credentials Rust SDKCVE-2026-48287
0

CVE-2026-48287 is an Untrusted Search Path vulnerability in Adobe Content Credentials Rust SDK that could allow arbitrary code execution with user interaction. Exploitation requires a victim to visit a malicious URL or interact with a compromised web page. The vulnerability affects the current user's context and changes the security scope. No specific affected versions or patches are currently identified.

Join the discussion
CVE-2026-48275: Untrusted Search Path (CWE-426) in Adobe Illustrator Desktop 2026CVE-2026-48275
0

Adobe Illustrator Desktop 2026 is affected by an Untrusted Search Path vulnerability (CWE-426) that could allow arbitrary code execution with high impact on confidentiality, integrity, and availability. Exploitation requires user interaction by opening a malicious file. The vulnerability changes the security scope and has a high CVSS score of 8.6. No patch or official remediation guidance is currently provided by the vendor.

Join the discussion
CVE-2026-48346: Untrusted Search Path (CWE-426) in Adobe Adobe Animate 2023CVE-2026-48346
0

Adobe Animate 2023 is affected by an Untrusted Search Path vulnerability (CWE-426) that could allow arbitrary code execution with the privileges of the current user. Exploitation requires user interaction, specifically opening a malicious file. The vulnerability impacts confidentiality and integrity, but not availability. No patch or official remediation has been confirmed yet.

Join the discussion
CVE-2026-57097: CWE-426: Untrusted Search Path in Microsoft Windows 10 Version 1607CVE-2026-57097
0

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

Join the discussion
CVE-2025-40945: CWE-426: Untrusted Search Path in Siemens COMOS V10.4.5CVE-2025-40945
0

A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: cwe-426
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses