HIGHVulnerability
CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Properties
- severity
- HIGH
- score
- 7.1
- cve_id
- CVE-2026-4786
- vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
- published_at
- 2026-04-13T22:16:30.413
- last_modified
- 2026-08-05T01:16:46.183
Related Entities (3)
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
→[Weakness]Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph