Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4786

31
FAUCET Score

CVE-2026-4786 is a bypass vulnerability affecting products that use the webbrowser.open() API, resulting from incomplete mitigation of CVE-2026-4519. The flaw allows attackers to bypass previous security patches by crafting URLs containing "%action" strings, which can lead to arbitrary command injection into the underlying shell on certain browser types. This vulnerability represents a second-order attack that exploits gaps in the initial remediation effort. The attack vector is network-based and requires user interaction through a crafted URL, suggesting low to medium complexity for exploitation. The potential impact includes arbitrary command execution with the privileges of the affected application, though the CVSS score is not currently available for precise severity assessment. The FAUCET Risk Score of 46.0/100 indicates moderate concern. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.0002 indicates minimal probability of exploitation within the next 30 days. Community attention appears limited, suggesting either recent disclosure or low visibility within security circles at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.14CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.0HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 21st percentile among its peer group of 1,570 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026
microsoft2026-Apr/CVE-2026-4786Important

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:10117
access.redhat.com / errata/RHSA-2026:10140
access.redhat.com / errata/RHSA-2026:10141
access.redhat.com / errata/RHSA-2026:10711
access.redhat.com / errata/RHSA-2026:10745
access.redhat.com / errata/RHSA-2026:10774
access.redhat.com / errata/RHSA-2026:10949
access.redhat.com / errata/RHSA-2026:10950
access.redhat.com / errata/RHSA-2026:11062
access.redhat.com / errata/RHSA-2026:11077
access.redhat.com / errata/RHSA-2026:11768
access.redhat.com / errata/RHSA-2026:13692
access.redhat.com / errata/RHSA-2026:13812
access.redhat.com / errata/RHSA-2026:14652
access.redhat.com / errata/RHSA-2026:14653
access.redhat.com / errata/RHSA-2026:14656
access.redhat.com / errata/RHSA-2026:16699
access.redhat.com / errata/RHSA-2026:17525
access.redhat.com / errata/RHSA-2026:17619
access.redhat.com / errata/RHSA-2026:19019
access.redhat.com / errata/RHSA-2026:19064
access.redhat.com / errata/RHSA-2026:19175
access.redhat.com / errata/RHSA-2026:19176
access.redhat.com / errata/RHSA-2026:19177
access.redhat.com / errata/RHSA-2026:19216
access.redhat.com / errata/RHSA-2026:19549
access.redhat.com / errata/RHSA-2026:19570
access.redhat.com / errata/RHSA-2026:19571
access.redhat.com / errata/RHSA-2026:19576
access.redhat.com / errata/RHSA-2026:19589
access.redhat.com / errata/RHSA-2026:19590
access.redhat.com / errata/RHSA-2026:21275
access.redhat.com / errata/RHSA-2026:21682
access.redhat.com / errata/RHSA-2026:22144
access.redhat.com / errata/RHSA-2026:25096
access.redhat.com / errata/RHSA-2026:26187
access.redhat.com / errata/RHSA-2026:28247
access.redhat.com / errata/RHSA-2026:28581
access.redhat.com / errata/RHSA-2026:30078
access.redhat.com / errata/RHSA-2026:30087
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / errata/RHSA-2026:35838
access.redhat.com / errata/RHSA-2026:8822
access.redhat.com / errata/RHSA-2026:8824
access.redhat.com / errata/RHSA-2026:9228
access.redhat.com / security/cve/CVE-2026-4786
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-4786.json
github.com / python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53
github.com / python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca
github.com / python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff
github.com / python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4
github.com / python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769
github.com / python/cpython/issues/148169
github.com / python/cpython/pull/148170
mail.python.org / archives/list/[email protected]/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5