CVE-2026-4786

EUVD-2026-22134
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PSFCNA
7 HIGH
LOCAL
LOW
NONE
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pythoncpython
𝑥
< 3.15.0
CNA
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libpython3_10-1_0
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
libpython3_12-1_0
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
libpython3_4m1_0
suse enterprise server 12 SP3
3.4.10-25.185.1
fixed
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
libpython3_4m1_0-32bit
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
libpython3_6m1_0
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
libpython3_9-1_0
suse enterprise server 15 SP5
3.9.25-150300.4.106.1
fixed
python3
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 12 SP3
3.4.10-25.185.1
fixed
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-base
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 12 SP3
3.4.10-25.185.1
fixed
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-curses
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 12 SP3
3.4.10-25.185.1
fixed
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-dbm
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-devel
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-idle
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-tk
suse enterprise desktop 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise sap 15 SP7
3.6.15-150300.10.118.1
fixed
suse enterprise server 12 SP5
3.4.10-25.185.1
fixed
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP7
3.6.15-150300.10.118.1
fixed
python3-tools
suse enterprise server 15 SP4
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP5
3.6.15-150300.10.118.1
fixed
suse enterprise server 15 SP6
3.6.15-150300.10.118.1
fixed
python310
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-base
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-curses
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-dbm
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-devel
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-idle
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-tk
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python310-tools
suse enterprise server 15 SP4
3.10.20-150400.4.112.1
fixed
python312
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-base
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-curses
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-dbm
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-devel
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-idle
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-tk
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python312-tools
suse enterprise server 15 SP6
3.12.13-150600.3.59.1
fixed
python39
suse enterprise server 15 SP5
3.9.25-150300.4.106.1
fixed
python39-base
suse enterprise server 15 SP5
3.9.25-150300.4.106.1
fixed
python39-curses
suse enterprise server 15 SP5
3.9.25-150300.4.106.1
fixed
python39-dbm
suse enterprise server 15 SP5
3.9.25-150300.4.106.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
platform-python
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
platform-python-debug
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
platform-python-devel
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
python-unversioned-command
RHEL 9
0:3.9.25-7.el9_8
fixed
python3
RHEL 9
0:3.9.25-7.el9_8
fixed
python3-debug
RHEL 9
0:3.9.25-7.el9_8
fixed
python3-devel
RHEL 9
0:3.9.25-7.el9_8
fixed
python3-idle
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
RHEL 9
0:3.9.25-7.el9_8
fixed
python3-libs
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
RHEL 9
0:3.9.25-7.el9_8
fixed
python3-test
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
RHEL 9
0:3.9.25-7.el9_8
fixed
python3-tkinter
RHEL 8
0:3.6.8-76.el8_10
fixed
RHEL 8.4 AUS
0:3.6.8-39.el8_4.11
fixed
RHEL 8.6 AUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 E4S
0:3.6.8-47.el8_6.13
fixed
RHEL 8.6 TUS
0:3.6.8-47.el8_6.13
fixed
RHEL 8.8 E4S
0:3.6.8-51.el8_8.15
fixed
RHEL 8.8 TUS
0:3.6.8-51.el8_8.15
fixed
RHEL 9
0:3.9.25-7.el9_8
fixed
python3.11
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.11-debug
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.11-devel
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.11-idle
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.11-libs
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.11-rpm-macros
RHEL 8
0:3.11.13-7.el8_10
fixed
python3.11-test
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.11-tkinter
RHEL 8
0:3.11.13-7.el8_10
fixed
RHEL 9
0:3.11.13-9.el9_8
fixed
python3.12
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.12-debug
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.12-devel
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.12-idle
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.12-libs
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.12-rpm-macros
RHEL 8
0:3.12.13-2.el8_10
fixed
python3.12-test
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.12-tkinter
RHEL 8
0:3.12.13-2.el8_10
fixed
RHEL 9
0:3.12.13-2.el9_8
fixed
python3.14
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-debug
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-devel
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading-debug
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading-devel
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading-idle
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading-libs
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading-test
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-freethreading-tkinter
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-idle
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-libs
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-test
RHEL 9
0:3.14.4-2.el9_8
fixed
python3.14-tkinter
RHEL 9
0:3.14.4-2.el9_8
fixed