Fallos del tipo CWE-426

322 resultados

Busca em caminho não confiável

Ocorre quando uma aplicação procura por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo não é totalmente controlado, permitindo que um atacante injete uma versão maliciosa de um arquivo antes da legítima ser encontrada. O risco é a execução de código não autorizado com os privilégios da aplicação.

Ejemplo

Uma aplicação precisa carregar a biblioteca 'libssl.so'. Se o PATH inclui o diretório /tmp antes de /usr/lib, um atacante coloca uma libssl.so maliciosa em /tmp — a aplicação carregará a falsa sem saber. Comum em scripts e instaladores que não usam caminhos absolutos.

Cómo mitigar

Use caminhos absolutos e completos ao fazer busca de arquivos críticos (não confie em PATH ou variáveis de ambiente). Valide integridade e propriedade de arquivos encontrados; configure o PATH explicitamente apenas com diretórios confiáveis; em sistemas Unix, remova '.' e /tmp da ordem de busca.

CVE-2025-24830MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24827MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24828MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2026-35368HIGHuutils coreutils chroot Local Privilege Escalation and chroot Escape in via Name Service Switch (NSS) InjectionEPSS 0.1%CVE-2026-29089HIGHTimescaleDB uses untrusted search path during extension upgradeEPSS 0.1%CVE-2025-12793HIGHAn uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a EPSS 0.1%CVE-2026-53842HIGHOpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment VariableEPSS 0.1%CVE-2026-32009HIGHOpenClaw < 2026.2.24 - Binary Hijacking via Static Default Trusted Directories in safeBinsEPSS 0.1%CVE-2025-30407MEDIUMLocal privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (EPSS 0.1%CVE-2026-40947LOWYubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.EPSS 0.1%CVE-2026-82862HIGHHulumi before v1.3.2 Helper Script Shadowing via Workspace FilesEPSS 0.1%CVE-2026-32015HIGHOpenClaw 2026.1.21 < 2026.2.19 - PATH Hijacking Bypass in tools.exec.safeBins Allowlist ValidationEPSS 0.1%CVE-2025-67722MEDIUMAuthenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalationEPSS 0.1%CVE-2026-32032HIGHOpenClaw < 2026.2.22 - Arbitrary Shell Execution via Unvalidated SHELL Environment VariableEPSS 0.1%CVE-2026-4545HIGHFlos Freeware Notepad2 PROPSYS.dll uncontrolled search pathEPSS 0.1%CVE-2024-14012HIGHPotential Privilege Escalation in Revenera InstallShield 2023 R1EPSS 0.1%CVE-2026-53858HIGHOpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment VariableEPSS 0.1%CVE-2026-16869HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-53865HIGHOpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATHEPSS 0.1%CVE-2026-32016HIGHOpenClaw < 2026.2.22 - Path Traversal via Basename-Only Allowlist Matching on macOSEPSS 0.1%