Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

BDU:2026-09777

CVSS: 6.6
13.04.2026

Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольные команды

Уязвимость модуля webbrowser интерпретатора языка программирования Python (CPython) связана с непринятием мер по очистке данных на управляющем уровне. Эксплуатация уязвимости может позволить нарушителю выполнить произвольные команды
Статус уязвимости:
Подтверждена производителем
Уязвимость устранена
Дата выявления: 13.04.2026
Класс уязвимости: Уязвимость кода
Наличие эксплойта: Данные уточняются
Способ эксплуатации: Инъекция
Способ устранения: Нет данных
Меры по устранению: Использование рекомендаций:
Для CPython:
https://github.com/python/cpython/pull/148170
https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53
https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca
https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff
https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4
https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769

Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&;q=CVE-2026-4786

Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-4786

Для Ubuntu:
https://ubuntu.com/security/CVE-2026-4786

Идентификатор типа ошибки

Идентификатор, установленный в соответствии с общим перечнем ошибок CWE
Идентификатор Описание
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Идентификаторы CVE уязвимостей

Идентификатор, базы данных общеизвестных уязвимостей информационной безопасности
Идентификатор Описание
CVE-2026-4786 Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

CVSS

Система общей оценки уязвимостей
Оценка Severity Версия Базовый вектор
6.6 MEDIUM 2.0 AV:L/AC:L/Au:N/C:C/I:C/A:N

Идентификаторы других систем описаний уязвимостей

CVE-2026-4786
Вендор:
  • Red Hat Inc.
  • ООО «Ред Софт»
  • Canonical Ltd.
  • Python Software Foundation
Тип ПО:
  • Операционная система
  • Прикладное ПО информационных систем
Наименование ПО:
  • Red Hat Enterprise Linux
  • РЕД ОС
  • Ubuntu
  • Red Hat AI Inference Server
  • Red Hat Update Infrastructure
  • Red Hat Hardened Images
  • RHEL-8 based Middleware Containers
  • Red Hat Enterprise Linux AI
  • CPython
Версия ПО:
  • 8 (Red Hat Enterprise Linux)
  • 6 Extended Lifecycle Support (Red Hat Enterprise Linux)
  • 7.3 (РЕД ОС)
  • 22.04 LTS (Ubuntu)
  • 9 (Red Hat Enterprise Linux)
  • 8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
  • 24.04 LTS (Ubuntu)
  • 9.0 Update Services for SAP Solutions (Red Hat Enterprise Linux)
  • 8.6 Update Services for SAP Solutions (Red Hat Enterprise Linux)
  • 8.6 Telecommunications Update Service (Red Hat Enterprise Linux)
  • 8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
  • 7 Extended Lifecycle Support (Red Hat Enterprise Linux)
  • 9.4 Extended Update Support (Red Hat Enterprise Linux)
  • 10 (Red Hat Enterprise Linux)
  • 8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
  • 8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
  • 9.2 Update Services for SAP Solutions (Red Hat Enterprise Linux)
  • 8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
  • 9.6 Extended Update Support (Red Hat Enterprise Linux)
  • 8.0 (РЕД ОС)
  • 10.0 Extended Update Support (Red Hat Enterprise Linux)
  • 3.2 (Red Hat AI Inference Server)
  • 5 (Red Hat Update Infrastructure)
  • - (Red Hat Hardened Images)
  • 26.04 LTS (Ubuntu)
  • - (RHEL-8 based Middleware Containers)
  • 3.3 (Red Hat AI Inference Server)
  • 3.3 (Red Hat Enterprise Linux AI)
  • до 3.13.14 (CPython)
  • от 3.14.0a1 до 3.14.5rc1 (CPython)
  • от 3.15.0a1 до 3.15.0b1 (CPython)
ОС и аппаратные платформы:
  • Red Hat Enterprise Linux (8)
  • Red Hat Enterprise Linux (6 Extended Lifecycle Support)
  • РЕД ОС (7.3)
  • Ubuntu (22.04 LTS)
  • Red Hat Enterprise Linux (9)
  • Red Hat Enterprise Linux (8.4 Advanced Mission Critical Update Support)
  • Ubuntu (24.04 LTS)
  • Red Hat Enterprise Linux (9.0 Update Services for SAP Solutions)
  • Red Hat Enterprise Linux (8.6 Update Services for SAP Solutions)
  • Red Hat Enterprise Linux (8.6 Telecommunications Update Service)
  • Red Hat Enterprise Linux (8.6 Advanced Mission Critical Update Support)
  • Red Hat Enterprise Linux (7 Extended Lifecycle Support)
  • Red Hat Enterprise Linux (9.4 Extended Update Support)
  • Red Hat Enterprise Linux (10)
  • Red Hat Enterprise Linux (8.8 Telecommunications Update Service)
  • Red Hat Enterprise Linux (8.8 Update Services for SAP Solutions)
  • Red Hat Enterprise Linux (9.2 Update Services for SAP Solutions)
  • Red Hat Enterprise Linux (8.4 Extended Update Support Long-Life Add-On)
  • Red Hat Enterprise Linux (9.6 Extended Update Support)
  • РЕД ОС (8.0)
  • Red Hat Enterprise Linux (10.0 Extended Update Support)
  • Ubuntu (26.04 LTS)
  • Red Hat Enterprise Linux AI (3.3)
Ссылки на источники:

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.