---
cve: "CVE-2026-4786"
severity: "HIGH"
cvss: 7.0
epss: "29%"
vendor: "Python Software Foundation"
kev: false
exploited: false
published: "2026-04-13 22:16:30"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T15:40:26+02:00"
---

# CVE-2026-4786

> 7.0 HIGH · 🧪 PoC

## Beschreibung

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Patch verfügbar (OSV)

- 3a19c2f0b3e91ce8f23d0cc64d4c9ee557823f24 (Commit)
- 41388c9cb160d0886d5ca00d2e6c8782608a4549 (Commit)

## Referenzen

- <https://github.com/python/cpython/pull/148170>
- <https://github.com/python/cpython/issues/148169>
- <https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/>
- <https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca>
- <https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff>
- <https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769>
- <https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53>
- <https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4>
- <https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744>
- <https://access.redhat.com/errata/RHSA-2026:10117>
- <https://access.redhat.com/errata/RHSA-2026:10140>
- <https://access.redhat.com/errata/RHSA-2026:10141>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-4786) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
