CWE-426 不可信的搜索路径 类弱点 194 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-426 属于不信任搜索路径漏洞,指程序使用外部提供的路径查找关键资源,导致可能访问不受控的文件。攻击者常通过操纵环境变量或配置,将恶意程序或数据注入搜索路径,从而执行任意代码或窃取敏感信息。开发者应避免使用动态搜索路径,改用硬编码的绝对路径,或严格验证路径来源及权限,确保仅加载受信任目录下的资源,以阻断攻击链。
#define DIR "/restricted/directory" char cmd[500]; sprintf(cmd, "ls -l %480s", DIR); /* Raise privileges to those needed for accessing DIR. */ RaisePrivileges(...); system(cmd); DropPrivileges(...); ...The user sets the PATH to reference a directory under the attacker's control, such as "/my/dir/". The attacker creates a malicious program called "ls", and puts that program in /my/dir The user executes the program. When system() is executed, the shell consults the PATH to find the ls program The program finds the attacker's malicious program, "/my/dir/ls". It doesn't find "/bin/ls" because PATH does not contain "/bin/". The program executes the attacker's malicious program with the raised privileges.... String home = System.getProperty("APPHOME"); String cmd = home + INITCMD; java.lang.Runtime.getRuntime().exec(cmd); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-7309 | Red Hat OpenShift Container Platform 代码问题漏洞 — Red Hat OpenShift Container Platform 4 | 4.3 | Medium | 2026-04-28 |
| CVE-2026-35368 | uutils coreutils 代码问题漏洞 — coreutils | 7.2 | High | 2026-04-22 |
| CVE-2026-35603 | Claude Code 安全漏洞 — claude-code | 7.3AI | HighAI | 2026-04-17 |
| CVE-2026-40947 | Yubico多款产品 安全漏洞 — libfido2 | 2.9 | Low | 2026-04-15 |
| CVE-2026-27290 | Adobe Framemaker 代码问题漏洞 — Adobe Framemaker | 8.6 | High | 2026-04-14 |
| CVE-2026-39883 | OpenTelemetry-Go 代码问题漏洞 — opentelemetry-go | 9.8AI | CriticalAI | 2026-04-08 |
| CVE-2025-39666 | Checkmk 安全漏洞 — Checkmk | 7.8AI | HighAI | 2026-04-07 |
| CVE-2022-4987 | Belden Hirschmann Industrial HiVision 代码问题漏洞 — Hirschmann Industrial HiVision | 7.3 | High | 2026-04-03 |
| CVE-2026-3780 | Foxit PDF Reader和Foxit PDF Editor 安全漏洞 — Foxit PDF Reader | 7.3 | High | 2026-04-01 |
| CVE-2026-33156 | ScreenToGif 安全漏洞 — ScreenToGif | 7.8 | High | 2026-03-20 |
| CVE-2026-25792 | GreenShot 代码问题漏洞 — greenshot | 6.5 | Medium | 2026-03-20 |
| CVE-2026-32032 | OpenClaw 代码问题漏洞 — OpenClaw | 7.8 | High | 2026-03-19 |
| CVE-2026-32016 | OpenClaw 代码问题漏洞 — OpenClaw | 7.8 | High | 2026-03-19 |
| CVE-2026-32015 | OpenClaw 代码问题漏洞 — OpenClaw | 7.8 | High | 2026-03-19 |
| CVE-2026-32009 | OpenClaw 代码问题漏洞 — OpenClaw | 5.7 | Medium | 2026-03-19 |
| CVE-2026-21333 | Adobe Illustrator 代码问题漏洞 — Illustrator | 8.6 | High | 2026-03-10 |
| CVE-2026-25190 | Microsoft Windows GDI 代码问题漏洞 — Windows 10 Version 1607 | 7.8 | High | 2026-03-10 |
| CVE-2026-29089 | timescaledb 代码问题漏洞 — timescaledb | 8.8 | High | 2026-03-06 |
| CVE-2026-2998 | eAI ERP 代码问题漏洞 — ERP F2 | 7.8 | High | 2026-02-23 |
| CVE-2026-25926 | Notepad++ 代码问题漏洞 — notepad-plus-plus | 7.3 | High | 2026-02-18 |
| CVE-2026-25880 | sumatrapdf 代码问题漏洞 — sumatrapdf | 7.8 | High | 2026-02-09 |
| CVE-2025-15321 | Tanium Appliance 安全漏洞 — Tanium Appliance | 2.7 | Low | 2026-02-05 |
| CVE-2025-13491 | IBM App Connect Enterprise Certified Container 代码问题漏洞 — App Connect Enterprise Certified Container | 5.1 | Medium | 2026-02-05 |
| CVE-2026-0662 | Autodesk 3ds Max 代码问题漏洞 — 3ds Max | 7.8 | High | 2026-02-04 |
| CVE-2025-65078 | Lexmark Printers 安全漏洞 — MXTCT, MSNGM, MSTGM, MXNGM, MXTGM, CSNGV, CSTGV, CXTGV, MSNGW, MSTGW, MXTGW, CSTLS, CXTLS, MXTLS, CSTMM, CXTMM, CSTPC, CXTPC, MXTPM, MSNSN, MSTSN, MXTSN, CSNZJ, CSTZJ, CXNZJ, CXTZJ | 8.8AI | HighAI | 2026-02-03 |
| CVE-2026-24051 | OpenTelemetry-Go 代码问题漏洞 — opentelemetry-go | 7.0 | High | 2026-02-02 |
| CVE-2026-24070 | Native Instruments Native Access 安全漏洞 — Native Access | 5.5AI | MediumAI | 2026-02-02 |
| CVE-2026-23512 | sumatrapdf 代码问题漏洞 — sumatrapdf | 8.6 | High | 2026-01-14 |
| CVE-2026-21280 | Adobe Illustrator 代码问题漏洞 — Illustrator | 8.6 | High | 2026-01-13 |
| CVE-2026-20943 | Microsoft Office 代码问题漏洞 — Microsoft Office 2016 | 7.0 | High | 2026-01-13 |
CWE-426(不可信的搜索路径) 是常见的弱点类别,本平台收录该类弱点关联的 194 条 CVE 漏洞。