CWE-427

CWE-427 · 3 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-427, highest CVSS first.

  1. HIGH 7.8CVE-2026-18657

    An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.8CVE-2026-18656

    An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protection

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.7CVE-2026-66344

    NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

    AI risk analysis on Exploit-DB.ai →