CVE-2026-4786 is a bypass vulnerability affecting products that use the webbrowser.open() API, resulting from incomplete mitigation of CVE-2026-4519. The flaw allows attackers to bypass previous security patches by crafting URLs containing "%action" strings, which can lead to arbitrary command injection into the underlying shell on certain browser types. This vulnerability represents a second-order attack that exploits gaps in the initial remediation effort. The attack vector is network-based and requires user interaction through a crafted URL, suggesting low to medium complexity for exploitation. The potential impact includes arbitrary command execution with the privileges of the affected application, though the CVSS score is not currently available for precise severity assessment. The FAUCET Risk Score of 46.0/100 indicates moderate concern. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.0002 indicates minimal probability of exploitation within the next 30 days. Community attention appears limited, suggesting either recent disclosure or low visibility within security circles at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.13.14CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.