CVE-2026-12003Disclosure

HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

6.0/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-06-17); latest day: 1
  • 8 total mentions across 7 days

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-06-16: 1Mentions · 2026-06-17: 2Mentions · 2026-06-18: 1Mentions · 2026-06-23: 1Mentions · 2026-08-11: 1Mentions · 2026-08-13: 1Mentions · 2026-09-09: 1Exploit Tool / Code · 2026-08-11: 1Active Exploitation · 2026-08-11: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 1Technical Details · 2026-06-23: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-09: 106-1606-1706-1806-2308-1108-1309-09
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Active Exploitation
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-161
General1
2026-06-172
Disclosure2
2026-06-181
Disclosure1
2026-06-231
Disclosure1
2026-08-111
Active Exploitation1
2026-08-131
Disclosure1
2026-09-091
Disclosure1
Full discourse8 posts
  • Bishop Fox@bishopfox
    Disclosure

    New advisory: CVE-2026-12003 Bishop Fox found a Windows-specific Python vulnerability affecting versions 3.11–3.15 that can allow local privilege escalation under the right conditions. https://t.co/Up7YFRRe4v

    Post summary

    Bishop Fox released an advisory for CVE‑2026‑12003, noting a Windows‑specific Python LPE vulnerability in versions 3.11‑3.15, without any PoC, exploit code, active exploitation evidence, or patch information.

    2503182.0K
    26.3K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-12003: CPython: In-tree (development) search paths can be enabled without modifying install directory https://www.openwall.com/lists/oss-security/2026/06/16/8

    Post summary

    A new CVE for CPython is disclosed, noting that in‑tree development search paths can be enabled without altering the install directory; technical details are shared via the Openwall mailing list.

    01041446
    4.7K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Disclosure

    🚨 #GüvenlikBülteni #SiberGüvenlik: #Python Windows Kurulumlarında Yetki Yükseltme Açığı Tespit Edildi! #CyberSecurity Merhaba #Brolyz Windows üzerinde çalışan #Python (CPython) kurulumlarında, düşük yetkili kullanıcıların yetki yükseltmesine imkan tanıyabilen CVE-2026-12003 numaralı yeni bir güvenlik açığı ortaya çıktı. 📌 Ne Oldu? Açık, özellikle eski EXE yükleyicileriyle kurulan Python sürümlerinde kullanılan VPATH mekanizmasından kaynaklanıyor. Saldırganlar belirli dizinlere sahte yapılandırma dosyaları ve kütüphaneler yerleştirerek Python'un standart sistem kütüphaneleri yerine kendi zararlı kodlarını çalıştırmasını sağlayabiliyor. ⚠️ Riskler Neler? • Yerel yetki yükseltme (LPE) • Zararlı Python kodu çalıştırılması • Sistem süreçlerinin ele geçirilmesi • Güvenilir uygulamalara kod enjekte edilmesi • Kalıcılık ve yatay hareket senaryoları Özellikle yüksek yetkilerle çalışan Python servisleri bu saldırıdan etkilenebiliyor. 🛡️ Alınabilecek Önlemler 1️⃣ Eski Python kurulumlarını güncel kurulum yöneticilerine taşıyın. 2️⃣ Python dizinleri ve üst klasörlerdeki ACL izinlerini kontrol edin. 3️⃣ Standart kullanıcıların kritik dizinlere yazma yetkilerini kaldırın. 4️⃣ Geçici önlem olarak erişimi kısıtlanmış Modules klasörleri oluşturun. 📊 Neden Önemli? Bu açık doğrudan uzaktan istismar edilmese de, sisteme erişim elde etmiş saldırganların ayrıcalık yükseltmesi için etkili bir yöntem sunuyor. Özellikle #Windows sunucularında çalışan otomasyon ve servis altyapıları risk altında olabilir. 🔚 Sonuç Yetki yükseltme açıkları saldırı zincirlerinin en kritik halkalarından biridir. Python kullanılan sistemlerde dosya izinlerinin gözden geçirilmesi ve güncel kurulum yöntemlerine geçilmesi büyük önem taşıyor.

    Post summary

    A new CVE-2026-12003 LPE flaw in Windows‑based Python installations via the VPATH mechanism has been disclosed, with technical details and mitigation recommendations.

    1001065
    335 followersView on X
  • Behk@behkfox
    Disclosure

    New advisory: CVE-2026-12003 Bishop Fox found a Windows-specific Python vulnerability affecting versions 3.11–3.15 that can allow local privilege escalation under the right conditions. https://t.co/cBPdJa8OaG

    Post summary

    Bishop Fox reports a new Windows‑specific Python vulnerability (CVE-2026-12003) affecting versions 3.11–3.15 that can enable local privilege escalation under certain conditions.

    0000083
    68 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-12003 to escalate privileges on Windows Python installations through path traversal techniques. By manipulating VPATH variables, low-privilege users gain elevated access when privileged users execute the interpreter. Runtime segmentation helps limit blast radius when privilege escalation occurs within containerized environments. #Vulnerability #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/python-privilege-escalation-cve-2026-12003

    Post summary

    The post reports that attackers are actively exploiting CVE-2026‑12003 by manipulating VPATH variables to achieve privilege escalation on Windows Python installations.

    0000063
    1.9K followersView on X
  • Can Artuc@canartuc
    Disclosure

    If you run Python on Windows, CVE-2026-12003 affects you: 3.11.15, 3.12.13, 3.13.14, 3.14.6, 3.15.0b2 and earlier all let a low-privilege user inject libraries via a path CPython checks for in-tree builds. Rated 5.3. How fast can your fleet patch every CPython version it ships?

    Post summary

    The post discloses that Windows users of CPython 3.11.15 through 3.15.0b2 (and earlier) are vulnerable to CVE‑2026‑12003 via library injection, lists the affected releases and CVSS score, and urges rapid patching.

    0000039
    171 followersView on X
  • Can Artuc@canartuc
    Disclosure

    Jake Yamaki of Bishop Fox found CVE-2026-12003: CPython uses a Modules/setup.local landmark to detect in-tree builds, so a low-privilege Windows user can create that path outside the install dir and inject libraries. CVSSv4 5.3. Should release builds ever look for landmarks?

    Post summary

    The tweet announces CVE‑2026‑12003, outlining how CPython’s in‑tree build detection can be abused to inject libraries by low‑privilege users, but does not provide a PoC, exploit, or patch.

    0000039
    171 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-12003 To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate cert… https://www.cve.org/CVERecord?id=CVE-2026-12003

    Post summary

    The text references CVE-2026-12003 with a brief mention of a build‑time variable and a link to the official record, but it provides no concrete details about exploitation, patching, or technical specifics.

    00000137
    57.6K followersView on X

Explore more