CVE-2026-4786Patch

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-04-14); latest day: 1
  • 8 total mentions across 7 days

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-04-13: 1Mentions · 2026-04-14: 2Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Mentions · 2026-05-18: 1Mentions · 2026-05-23: 1Mentions · 2026-06-27: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-27: 104-1304-1404-2504-2805-1805-2306-27
Signal classification3 categories
Patch
450.0%
General
225.0%
Disclosure
225.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-131
General1
2026-04-142
Disclosure1General1
2026-04-251
Disclosure1
2026-04-281
Patch1
2026-05-181
Patch1
2026-05-231
Patch1
2026-06-271
Patch1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4786: CPython: Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.⁠open() https://www.openwall.com/lists/oss-security/2026/04/13/11 High severity

    Post summary

    A new CVE (CVE‑2026‑4786) affecting CPython is announced, highlighting a command injection flaw in the webbrowser.open() function with an incomplete earlier mitigation, and classified as high severity.

    10030572
    4.6K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:28581 acaba de sair para Rocky Linux 10! Corrige CVE-2026-4786 (injeção de comandos em http://webbrowser.open()) e CVE-2026-6019. Saiba mais:- > http://tinyurl.com/3sfn6973 https://t.co/bBL9ozkMGO

    Post summary

    A Rocky Linux 10 advisory (RLSA-2026:28581) announces patches for two CVEs, including a command‑injection flaw, with additional details via a linked resource.

    1000076
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    CVE-2026-1502 (HTTP injection) and CVE-2026-4786 (command injection) hit Python 3.14 on Fedora. Don't just patch today. Build automation that finds ANY CVE. Read -> https://tinyurl.com/2krzcetb #Fedora #Security https://t.co/MAxXE6g3II

    Post summary

    The tweet announces new CVEs affecting Python 3.14 on Fedora, noting their types as HTTP and command injection, without providing PoC, exploitation details, or patch information.

    1000045
    1.5K followersView on X
  • Rob Savoury@RobSavoury
    Patch

    Latest Python 3.14.5 release (including fixes for CVE-2026-1502, CVE-2026-4786, and CVE-2026-5713) is now available to #SavOS PPA users of #Ubuntu #Linux at ppa:savoury1/python-3.14 (https://launchpad.net/~savoury1/+archive/ubuntu/python-3.14) for all PPA supported LTS releases.

    Post summary

    A new Python 3.14.5 package is now available on the SavOS PPA, providing patches for CVE‑2026‑1502, CVE‑2026‑4786, and CVE‑2026‑5713 for Ubuntu Linux users.

    0000075
    46 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: SUSE releases critical Python3 and Python310 patches for CVE-2026-1502, CVE-2026-4786 and 3 more flaws enabling command injection and code execution on openSUSE systems. https://threatcluster.io/cluster/critical-python-vulnerabilities-in-opensuse-affecting-comman-9dc1aaa1

    Post summary

    SUSE has issued critical patches for several Python3-related CVEs that allow command injection and code execution on openSUSE systems.

    0000064
    275 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora updates MinGW Windows python3 to patch CVE-2026-4786, CVE-2026-6100, CVE-2026-3479, CVE-2026-1502 enabling code execution, data leaks, and HTTP header injection. https://threatcluster.io/cluster/multiple-cves-addressed-in-fedora-python3-updates-f6a2a99b

    Post summary

    Fedora released a patch for python3 addressing several CVEs that could lead to code execution, data leaks, and HTTP header injection.

    0000063
    166 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "http://webbrowser.open()" API could h… https://www.cve.org/CVERecord?id=CVE-2026-4786

    Post summary

    The note indicates the mitigation for CVE‑2026‑4519 was incomplete and that URLs containing "%action" could bypass the protection on certain browsers, but provides no additional technical details or mitigation information.

    0000086
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4786 Incomplete CVE-2026-4519 Mitigation Allows Command Injection via URL Parameters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4786

    Post summary

    The brief entry references CVE‑2026‑4786 and links to a vulnerability detail page but provides no evidence of a PoC, active exploitation, patch, or technical specifics.

    0000033
    4.0K followersView on X

Explore more