CVE-2026-4786: CWE-77 in Python Software Foundation CPython
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
AI Analysis
Technical Summary
CVE-2026-4786 is a command injection vulnerability in the Python webbrowser.open() API. If a URL containing the string "%action" is processed, it can bypass the mitigation implemented for CVE-2026-4519, allowing an attacker to inject commands into the underlying shell and achieve arbitrary code execution. This flaw affects CPython versions including 3.11.0, 3.12.0, 3.13.0, 3.14.0, 3.15.0, and their alpha releases. The vulnerability is tracked under CWE-77 and CWE-88, indicating improper neutralization of argument delimiters leading to command injection. Red Hat has published advisories and released security updates for affected products, particularly for Red Hat Enterprise Linux Extended Lifecycle Support versions. However, a general mitigation for all affected versions is not currently available or does not meet Red Hat's criteria for deployment.
Potential Impact
An attacker can exploit this vulnerability by crafting a URL containing "%action" that, when processed by the webbrowser.open() API, injects arbitrary commands into the underlying shell. This can lead to arbitrary code execution, compromising confidentiality, integrity, and availability of the affected system. The vulnerability bypasses a previous mitigation, increasing the risk of exploitation. The CVSS v3 score is 7.1 (high severity), with high impact on confidentiality and integrity, and low impact on availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released security updates addressing CVE-2026-4786 for their supported products, including Red Hat Enterprise Linux Server Extended Lifecycle Support Extension 6. Users should apply these updates as soon as possible. Currently, no universal mitigation is available or meets Red Hat's criteria for ease of use and deployment. Users of affected CPython versions should monitor vendor advisories for patches and updates. For Red Hat customers, consulting with a Technical Account Manager (TAM) is recommended for tailored guidance. No additional mitigations are specified beyond applying the vendor-provided updates.
CVE-2026-4786: CWE-77 in Python Software Foundation CPython
Description
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVSS v4.0
Score 7.0high
Affected software
Python Software Foundation
CPython
pkg:github/CPythonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-4786 is a command injection vulnerability in the Python webbrowser.open() API. If a URL containing the string "%action" is processed, it can bypass the mitigation implemented for CVE-2026-4519, allowing an attacker to inject commands into the underlying shell and achieve arbitrary code execution. This flaw affects CPython versions including 3.11.0, 3.12.0, 3.13.0, 3.14.0, 3.15.0, and their alpha releases. The vulnerability is tracked under CWE-77 and CWE-88, indicating improper neutralization of argument delimiters leading to command injection. Red Hat has published advisories and released security updates for affected products, particularly for Red Hat Enterprise Linux Extended Lifecycle Support versions. However, a general mitigation for all affected versions is not currently available or does not meet Red Hat's criteria for deployment.
Potential Impact
An attacker can exploit this vulnerability by crafting a URL containing "%action" that, when processed by the webbrowser.open() API, injects arbitrary commands into the underlying shell. This can lead to arbitrary code execution, compromising confidentiality, integrity, and availability of the affected system. The vulnerability bypasses a previous mitigation, increasing the risk of exploitation. The CVSS v3 score is 7.1 (high severity), with high impact on confidentiality and integrity, and low impact on availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released security updates addressing CVE-2026-4786 for their supported products, including Red Hat Enterprise Linux Server Extended Lifecycle Support Extension 6. Users should apply these updates as soon as possible. Currently, no universal mitigation is available or meets Red Hat's criteria for ease of use and deployment. Users of affected CPython versions should monitor vendor advisories for patches and updates. For Red Hat customers, consulting with a Technical Account Manager (TAM) is recommended for tailored guidance. No additional mitigations are specified beyond applying the vendor-provided updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PSF
- Date Reserved
- 2026-03-24T19:25:48.269Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-4786","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22144","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19589","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13812","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16699","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10711","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19064","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19019","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28581","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11077","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11062","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10950","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19590","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17619","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19549","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26187","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19571","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19570","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:13692","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21682","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14653","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17525","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19576","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14652","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:14656","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10949","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10774","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10745","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19216","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19175","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19177","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19176","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28247","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25096","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30078","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30089","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30088","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30087","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10140","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10141","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8822","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:8824","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10117","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:9228","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:11768","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21275","vendor":"Red Hat"}]
Threat ID: 69dd67d182d89c981f6a0138
Added to database: 04/13/2026, 22:01:53 UTC
Last enriched: 08/13/2026, 13:10:40 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 280
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.