VulnSea

CWE-426

CVEs classified under CWE-426, newest first.

42 CVEsRSS

CVE-2026-92587Medium· 5.0
5d ago

n8n is a workflow automation platform

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git …

Sunlitn8n-io · n8nEPSS 0.18%via NVD
CVE-2026-0307Medium· 5.9
1w ago

GlobalProtect App: Local Privilege Escalation Vulnerabilities

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administr…

SunlitPalo Alto Networks · GlobalProtect AppEPSS 0.10%via CVEORG
CVE-2026-81192High· 7.0
1w ago

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute dete…

Twilightopen-telemetry · opentelemetry-dotnet-contribEPSS 0.14%via NVD
CVE-2026-80159Medium· 4.0
1w ago

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions bey…

Sunlitadobe · acrobatEPSS 0.11%via NVD
CVE-2026-78574High· 7.5
1w ago

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, re…

TwilightOkta · Okta Hyperdrive Integration PluginEPSS 0.10%via NVD
CVE-2026-69785High· 7.8
1w ago

Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.31%via NVD
CVE-2026-69328High· 7.8PoC
1w ago

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

MidnightMicrosoft · Windows 10 Version 1607EPSS 0.31%via NVD
CVE-2026-84226High· 8.5
2w ago

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

TwilightOpenVPN · OpenVPNEPSS 0.14%via NVD
CVE-2026-78680High· 7.8
2w ago

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

Twilightnltk · nltkEPSS 0.12%via OSV
CVE-2026-78155Critical· 9.9
4w ago

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Midnightongres · stackgresEPSS 0.29%via NVD
CVE-2026-55769None
1mo ago

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/manage…

SunlitEPSS 0.68%via NVD
CVE-2026-16869High· 7.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.

Twilightibm · viosEPSS 0.12%via NVD
CVE-2026-14673Low· 3.8
1mo ago

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path befor…

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path befor…

Sunlitpostgresql · postgresqlEPSS 0.17%via NVD
CVE-2026-56174High· 7.8
1mo ago

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1809EPSS 0.29%via NVD
CVE-2026-55522High· 7.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…

Twilightpraisonaiagents · praisonaiagentsEPSS 0.15%via NVD
CVE-2026-47211High
1mo ago

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands …

Twilightouroboros-ai · ouroboros-aiEPSS 0.17%via NVD
CVE-2026-11400High· 8.0
2mo ago

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Twilightamazon · software.amazon.jdbc:aws-advanced-jdbc-wrapperEPSS 0.30%via GHSA
CVE-2026-57097Medium· 6.4
2mo ago

Microsoft XML Security Feature Bypass Vulnerability

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.50%via CVEORG
CVE-2026-15515High· 7.0
2mo ago

A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301

A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path.…

TwilightEPSS 0.16%via NVD
CVE-2026-53819High· 8.8
2mo ago

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

Twilightopenclaw · openclawEPSS 0.30%via GHSA
CVE-2026-57919High· 7.8
2mo ago

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker…

TwilightEPSS 0.18%via NVD
CVE-2026-53842High· 7.1
3mo ago

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

Twilightopenclaw · openclawEPSS 0.13%via GHSA
CVE-2026-53846High· 7.1
3mo ago

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

Twilightopenclaw · openclawEPSS 0.12%via GHSA
CVE-2026-53858High· 7.1
3mo ago

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

Twilightopenclaw · openclawEPSS 0.12%via GHSA
CVE-2026-53865High· 7.1
3mo ago

OpenClaw: Workspace-derived service PATH could influence trash command selection

OpenClaw: Workspace-derived service PATH could influence trash command selection

Twilightopenclaw · openclawEPSS 0.12%via GHSA
CVE-2026-12003High· 7.8
3mo ago

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark i…

TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.15%via NVD
GHSA-9fr2-p65v-gqxqHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

Duplicate Advisory: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

Twilightopenclaw · openclawvia GHSA
GHSA-qp5j-jr73-m2pwHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install

Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install

Twilightopenclaw · openclawvia GHSA
GHSA-4qgr-57jq-93vhHigh· 7.1
3mo ago

Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

Twilightopenclaw · openclawvia GHSA
GHSA-2w22-3f6x-3hf4High· 7.1
3mo ago

Duplicate Advisory: Workspace-derived service PATH could influence trash command selection

Duplicate Advisory: Workspace-derived service PATH could influence trash command selection

Twilightopenclaw · openclawvia GHSA
CWE-426 vulnerabilities (CVEs) · VulnSea