Weaknesses of type CWE-426

322 results

Caminho de busca não confiável

Ocorre quando a aplicação busca por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Se um diretório não confiável vem antes de um diretório legítimo no PATH (ou em lógica de busca customizada), o atacante injeta um arquivo malicioso com o mesmo nome para ser carregado no lugar do original.

Example

Um software Windows busca 'config.dll' primeiro no diretório atual antes de procurar em System32. Um atacante coloca uma DLL maliciosa com esse nome na pasta de trabalho; quando o software executa, carrega a versão maliciosa e compromete a máquina.

How to mitigate

Especifique sempre caminhos absolutos completos ao carregar bibliotecas e executáveis, evitando buscas dinâmicas em PATH. Em Unix/Linux, remova ou coloque o diretório atual (.) ao final do PATH, nunca no início; no Windows, configure DLL search order e use mecanismos como SetDllDirectory para restringir onde as DLLs são procuradas.

CVE-2025-24830MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24827MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24828MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-35368HIGHuutils coreutils chroot Local Privilege Escalation and chroot Escape in via Name Service Switch (NSS) InjectionEPSS 0.1%CVE-2026-29089HIGHTimescaleDB uses untrusted search path during extension upgradeEPSS 0.1%CVE-2025-12793HIGHAn uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a EPSS 0.1%CVE-2026-53842HIGHOpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment VariableEPSS 0.1%CVE-2026-32009HIGHOpenClaw < 2026.2.24 - Binary Hijacking via Static Default Trusted Directories in safeBinsEPSS 0.1%CVE-2025-30407MEDIUMLocal privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (EPSS 0.1%CVE-2026-40947LOWYubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.EPSS 0.1%CVE-2026-82862HIGHHulumi before v1.3.2 Helper Script Shadowing via Workspace FilesEPSS 0.1%CVE-2026-32015HIGHOpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist ValidationEPSS 0.1%CVE-2025-67722MEDIUMAuthenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalationEPSS 0.1%CVE-2026-32032HIGHOpenClaw < 2026.2.22 - Arbitrary Shell Execution via Unvalidated SHELL Environment VariableEPSS 0.1%CVE-2026-4545HIGHFlos Freeware Notepad2 PROPSYS.dll uncontrolled search pathEPSS 0.1%CVE-2024-14012HIGHPotential Privilege Escalation in Revenera InstallShield 2023 R1EPSS 0.1%CVE-2026-53858HIGHOpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment VariableEPSS 0.1%CVE-2026-16869HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-53865HIGHOpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHEPSS 0.1%CVE-2026-32016HIGHOpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOSEPSS 0.1%