High severity7.1NVD Advisory· Published Apr 13, 2026· Updated Aug 13, 2026
CVE-2026-4786
CVE-2026-4786
Description
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
70(expand)+ 1 more
- (no CPE)
- (no CPE)
- osv-coords68 versionspkg:apk/chainguard/python-3.10pkg:apk/chainguard/python-3.11pkg:apk/chainguard/python-3.13pkg:apk/chainguard/python-3.14pkg:apk/wolfi/python-3.10pkg:apk/wolfi/python-3.11pkg:apk/wolfi/python-3.13pkg:apk/wolfi/python-3.14pkg:bitnami/libpythonpkg:bitnami/pythonpkg:bitnami/python-minpkg:rpm/almalinux/platform-pythonpkg:rpm/almalinux/platform-python-debugpkg:rpm/almalinux/platform-python-develpkg:rpm/almalinux/python-unversioned-commandpkg:rpm/almalinux/python3pkg:rpm/almalinux/python3-debugpkg:rpm/almalinux/python3-develpkg:rpm/almalinux/python3-idlepkg:rpm/almalinux/python3-libspkg:rpm/almalinux/python3-testpkg:rpm/almalinux/python3-tkinterpkg:rpm/almalinux/python3.11pkg:rpm/almalinux/python3.11-debugpkg:rpm/almalinux/python3.11-develpkg:rpm/almalinux/python3.11-idlepkg:rpm/almalinux/python3.11-libspkg:rpm/almalinux/python3.11-rpm-macrospkg:rpm/almalinux/python3.11-testpkg:rpm/almalinux/python3.11-tkinterpkg:rpm/almalinux/python3.12pkg:rpm/almalinux/python3.12-debugpkg:rpm/almalinux/python3.12-develpkg:rpm/almalinux/python3.12-idlepkg:rpm/almalinux/python3.12-libspkg:rpm/almalinux/python3.12-rpm-macrospkg:rpm/almalinux/python3.12-testpkg:rpm/almalinux/python3.12-tkinterpkg:rpm/almalinux/python3.14pkg:rpm/almalinux/python3.14-debugpkg:rpm/almalinux/python3.14-develpkg:rpm/almalinux/python3.14-freethreadingpkg:rpm/almalinux/python3.14-freethreading-debugpkg:rpm/almalinux/python3.14-freethreading-develpkg:rpm/almalinux/python3.14-freethreading-idlepkg:rpm/almalinux/python3.14-freethreading-libspkg:rpm/almalinux/python3.14-freethreading-testpkg:rpm/almalinux/python3.14-freethreading-tkinterpkg:rpm/almalinux/python3.14-idlepkg:rpm/almalinux/python3.14-libspkg:rpm/almalinux/python3.14-testpkg:rpm/almalinux/python3.14-tkinterpkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python310&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python311&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python312&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python313&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python313&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python313-core&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python313-documentation&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python313-nogil&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python313-nogil-nogil-core&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python314&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python315&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/python313&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7pkg:rpm/suse/python313-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7
< 3.10.20-r3+ 67 more
- (no CPE)range: < 3.10.20-r3
- (no CPE)range: < 3.11.15-r2
- (no CPE)range: < 3.13.13-r2
- (no CPE)range: < 3.14.4-r3
- (no CPE)range: < 3.10.20-r3
- (no CPE)range: < 3.11.15-r2
- (no CPE)range: < 3.13.13-r2
- (no CPE)range: < 3.14.4-r3
- (no CPE)range: < 3.13.14
- (no CPE)range: < 3.13.14
- (no CPE)range: < 3.13.14
- (no CPE)range: < 3.6.8-76.el8_10.alma.1
- (no CPE)range: < 3.6.8-76.el8_10.alma.1
- (no CPE)range: < 3.6.8-76.el8_10.alma.1
- (no CPE)range: < 3.12.12-3.el10_1.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.9.25-3.el9_7.3
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.11.13-7.el8_10
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.11.13-5.3.el9_7
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.12.13-2.el8_10
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.12.12-4.el9_7.3
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.14.4-2.el10_2
- (no CPE)range: < 3.13.14-160000.1.1
- (no CPE)range: < 3.10.20-6.1
- (no CPE)range: < 3.11.15-6.1
- (no CPE)range: < 3.12.13-6.1
- (no CPE)range: < 3.13.14-160000.1.1
- (no CPE)range: < 3.13.13-2.1
- (no CPE)range: < 3.13.14-160000.1.1
- (no CPE)range: < 3.13.14-160000.1.1
- (no CPE)range: < 3.13.14-160000.1.1
- (no CPE)range: < 3.13.14-160000.1.1
- (no CPE)range: < 3.14.6-1.1
- (no CPE)range: < 3.15.0~a8-3.1
- (no CPE)range: < 2.7.18-150000.120.1
- (no CPE)range: < 2.7.18-150000.120.1
- (no CPE)range: < 3.13.13-150700.4.50.1
- (no CPE)range: < 3.13.13-150700.4.50.1
Patches
Vulnerability mechanics
References
58- access.redhat.com/errata/RHSA-2026:10117nvd
- access.redhat.com/errata/RHSA-2026:10140nvd
- access.redhat.com/errata/RHSA-2026:10141nvd
- access.redhat.com/errata/RHSA-2026:10711nvd
- access.redhat.com/errata/RHSA-2026:10745nvd
- access.redhat.com/errata/RHSA-2026:10774nvd
- access.redhat.com/errata/RHSA-2026:10949nvd
- access.redhat.com/errata/RHSA-2026:10950nvd
- access.redhat.com/errata/RHSA-2026:11062nvd
- access.redhat.com/errata/RHSA-2026:11077nvd
- access.redhat.com/errata/RHSA-2026:11768nvd
- access.redhat.com/errata/RHSA-2026:13692nvd
- access.redhat.com/errata/RHSA-2026:13812nvd
- access.redhat.com/errata/RHSA-2026:14652nvd
- access.redhat.com/errata/RHSA-2026:14653nvd
- access.redhat.com/errata/RHSA-2026:14656nvd
- access.redhat.com/errata/RHSA-2026:16699nvd
- access.redhat.com/errata/RHSA-2026:17525nvd
- access.redhat.com/errata/RHSA-2026:17619nvd
- access.redhat.com/errata/RHSA-2026:19019nvd
- access.redhat.com/errata/RHSA-2026:19064nvd
- access.redhat.com/errata/RHSA-2026:19175nvd
- access.redhat.com/errata/RHSA-2026:19176nvd
- access.redhat.com/errata/RHSA-2026:19177nvd
- access.redhat.com/errata/RHSA-2026:19216nvd
- access.redhat.com/errata/RHSA-2026:19549nvd
- access.redhat.com/errata/RHSA-2026:19570nvd
- access.redhat.com/errata/RHSA-2026:19571nvd
- access.redhat.com/errata/RHSA-2026:19576nvd
- access.redhat.com/errata/RHSA-2026:19589nvd
- access.redhat.com/errata/RHSA-2026:19590nvd
- access.redhat.com/errata/RHSA-2026:21275nvd
- access.redhat.com/errata/RHSA-2026:21682nvd
- access.redhat.com/errata/RHSA-2026:22144nvd
- access.redhat.com/errata/RHSA-2026:25096nvd
- access.redhat.com/errata/RHSA-2026:26187nvd
- access.redhat.com/errata/RHSA-2026:28247nvd
- access.redhat.com/errata/RHSA-2026:28581nvd
- access.redhat.com/errata/RHSA-2026:30078nvd
- access.redhat.com/errata/RHSA-2026:30087nvd
- access.redhat.com/errata/RHSA-2026:30088nvd
- access.redhat.com/errata/RHSA-2026:30089nvd
- access.redhat.com/errata/RHSA-2026:35838nvd
- access.redhat.com/errata/RHSA-2026:8822nvd
- access.redhat.com/errata/RHSA-2026:8824nvd
- access.redhat.com/errata/RHSA-2026:9228nvd
- access.redhat.com/security/cve/CVE-2026-4786nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53nvd
- github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744nvd
- github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bcanvd
- github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fffnvd
- github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4nvd
- github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769nvd
- github.com/python/cpython/issues/148169nvd
- github.com/python/cpython/pull/148170nvd
- mail.python.org/archives/list/[email protected]/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/nvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.jsonnvd
News mentions
0No linked articles in our index yet.