CVE-2026-4786

Aliases:UBUNTU-CVE-2026-4786DEBIAN-CVE-2026-4786ALPINE-CVE-2026-4786CGA-2pc5-wq55-g9c6CGA-32qm-4q47-64c2CGA-53c8-jf7x-64gmCGA-5cv4-jxr8-9chvCGA-6pqf-5rmg-x54jCGA-7vp4-6c8x-mjv8CGA-97m2-fx86-4q55CGA-gj4f-mjgp-c3mvCGA-238h-jpjh-8jq3CGA-26r6-g9vq-93vpCGA-xf3h-qjp5-9g8pCGA-xqw6-5r86-7mxx
Awaiting Analysis
Published: 13 Apr 2026, 21:52
Last modified:13 Aug 2026, 00:27

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7.1 HIGH
v3.1 (cve.org)
EPSS Score
0.29% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Apr 2026, 21:52
Published
Vulnerability first disclosed
13 Aug 2026, 00:27
Last Modified
Vulnerability information updated

Description

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS Metrics

  • v4.0HIGHScore: 7CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 7CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

EPSS Trends

Current EPSS score: 0.29% Percentile: 22%

Techniques & Countermeasures

  • CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')

    The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

  • CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

    The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Affected Systems

  • alpinepython3

    < 3.12.14-r0 | < 3.12.14-r0 | < 3.12.14-r0

  • chainguardpython-3.10

    < 3.10.20-r3

  • chainguardpython-3.11

    < 3.11.15-r2

  • chainguardpython-3.12

    < 3.12.14-r2

  • chainguardpython-3.13

    < 3.13.13-r2

  • chainguardpython-3.14

    < 3.14.4-r3

  • chainguardpython-3.9

    all

  • wolfipython-3.10

    < 3.10.20-r3

  • wolfipython-3.11

    < 3.11.15-r2

  • wolfipython-3.12

    < 3.12.14-r2

  • wolfipython-3.13

    < 3.13.13-r2

  • wolfipython-3.14

    < 3.14.4-r3

  • debianpypy3

    < 7.3.22+dfsg-1

  • debianpython3.13

    < 3.13.14-1

  • debianpython3.14

    < 3.14.5-1

  • ubuntujython

    all | all | all | all | all | all | all

  • ubuntupypy3

    all | all | all | all | all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    < 3.10.12-1~22.04.16

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.15

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | < 3.14.4-1ubuntu0.1

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.15.0 | < 3.13.14 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.14 | ≥ 3.14.0a1, < 3.14.5rc1 | ≥ 3.15.0a1, < 3.15.0b1

References (66)