CWE-427Base2 in KEV

Uncontrolled Search Path Element

Draft in the CWE catalog · 789 CVEs mapped

789
CVEs mapped
2
In KEV
7.3
Median CVSS
What it is

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Recent examples
7.8cvss
CVE-2026-6958

CVE-2026-6958 - HIGH Severity Vulnerability

Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation.

HIGHno explanation yet
0%
epss
7.8cvss
CVE-2026-45221

CVE-2026-45221 - HIGH Severity Vulnerability

Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On Windows, the missing directory resides in a location writable by any authenticated local user, enabling attackers to create the directory and place malicious files that execute at the privilege level of the user or service account that launches Konga, facilitating privilege escalation.

HIGHno explanation yet
0%
epss
7.3cvss
CVE-2026-19590

CVE-2026-19590 - HIGH Severity Vulnerability

OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-427
Abstraction
Base
Structure
Simple
Status
Draft
References (14)