CVE-2026-4786: Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Published Apr 13, 2026
·
Updated

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Other sources

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Red Hat

Affected Software

14 affected componentsFixes available
Python Software Foundation CPython
debian/jython
2.7.2+repack1-32.7.3+repack1-1
debian/pypy3
7.3.5+dfsg-2+deb11u27.3.5+dfsg-2+deb11u57.3.11+dfsg-2+deb12u37.3.19+dfsg-27.3.23+dfsg-1
debian/python2.7
2.7.18-8+deb11u1
debian/python3.11
3.11.2-6+deb12u73.11.2-6+deb12u3
debian/python3.13
3.13.5-2+deb13u23.13.14-1
debian/python3.14
3.14.6-1
debian/python3.9
3.9.2-13.9.2-1+deb11u7
IBM CICS Transaction Gateway for Multiplatforms<=9.1
IBM CICS Transaction Gateway for Multiplatforms<=9.2
IBM CICS Transaction Gateway for Multiplatforms<=9.3
IBM CICS Transaction Gateway for Multiplatforms<=10.1
Microsoft azl3 python3 3.12.9-13<3.12.9-14
3.12.9-14
Microsoft azl3 python3 3.12.9-14<3.12.9-14
3.12.9-14

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/jython to a version that resolves this vulnerability.

    Fixed in 2.7.2+repack1-3Fixed in 2.7.3+repack1-1
  2. Upgrade

    Upgrade debian/pypy3 to a version that resolves this vulnerability.

    Fixed in 7.3.5+dfsg-2+deb11u2Fixed in 7.3.5+dfsg-2+deb11u5Fixed in 7.3.11+dfsg-2+deb12u3Fixed in 7.3.19+dfsg-2Fixed in 7.3.23+dfsg-1
  3. Upgrade

    Upgrade debian/python2.7 to a version that resolves this vulnerability.

    Fixed in 2.7.18-8+deb11u1
  4. Upgrade

    Upgrade debian/python3.11 to a version that resolves this vulnerability.

    Fixed in 3.11.2-6+deb12u7Fixed in 3.11.2-6+deb12u3
  5. Upgrade

    Upgrade debian/python3.13 to a version that resolves this vulnerability.

    Fixed in 3.13.5-2+deb13u2Fixed in 3.13.14-1
  6. Upgrade

    Upgrade debian/python3.14 to a version that resolves this vulnerability.

    Fixed in 3.14.6-1
  7. Upgrade

    Upgrade debian/python3.9 to a version that resolves this vulnerability.

    Fixed in 3.9.2-1Fixed in 3.9.2-1+deb11u7
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 3.12.9-14

Event History

Apr 13, 2026
CVE Published
via MITRE·09:52 PM
Data Sourced
via MITRE·09:52 PM
DescriptionWeakness
Data Sourced
via Red Hat·10:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Apr 19, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Jul 6, 2026
Data Sourced
via Debian·01:33 PM
DescriptionAffected Software
Data Sourced
via Launchpad·01:33 PM
Description
Jul 8, 2026
Data Sourced
via Ubuntu·01:34 PM
RemedyDescriptionSeverityAffected Software
Jul 29, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-4786?

CVE-2026-4786 is classified as a medium severity vulnerability due to the potential for command injection through the webbrowser.open() API.

2

How do I fix CVE-2026-4786?

To fix CVE-2026-4786, ensure that your version of CPython is updated to the latest release that includes the necessary security patches.

3

What is the impact of CVE-2026-4786?

The impact of CVE-2026-4786 allows attackers to potentially inject commands into the webbrowser.open() API when using vulnerable versions of CPython.

4

Who is affected by CVE-2026-4786?

Users and developers using specific versions of CPython that utilize the webbrowser.open() API with URL input are affected by CVE-2026-4786.

5

What is the relationship between CVE-2026-4786 and CVE-2026-4519?

CVE-2026-4786 is an incomplete mitigation of CVE-2026-4519, indicating that the initial fix did not fully address the command injection vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203