Threat reportVulnerabilityTL-2026-2997

CVE-2026-12003: CPython on Windows VPATH uncontrolled search path (CWE-427) enables cross-account code execution and privilege escalation

mediumPATCHED

CVE-2026-12003 (TL-2026-2997), also tracked as CPython VPATH in-tree landmark search path hijack, is a medium-severity software vulnerability scored CVSS 5.3, first published 2026-08-05. It has no confirmed attribution, affects Python Software Foundation CPython (Windows), references 1 CVE (CVE-2026-12003), maps to 9 MITRE ATT&CK techniques (T1033, T1059.001, T1059.003), and is covered by 9 detection rules and 10 indicators of compromise.

CVSS
5.3/10Medium
CVEs
1Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-2997

Threat ID
TL-2026-2997
Also known as
CPython VPATH in-tree landmark search path hijack
Severity
MEDIUM
CVSS
5.3 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, health
Target regions
Global
Detection rules
9
Indicators of compromise
10

Malware and tooling in CVE-2026-12003

Malware and tooling: Python, robocopy

How CVE-2026-12003 works

CPython on Windows (3.11.0a3 through 3.15.0b2) resolves a build-time VPATH of ..\.. to look for a Modules\setup.local landmark outside the install directory. When Python is installed system-wide by the legacy EXE installer, a low-privilege user can create that landmark plus a Lib folder and get code run in another account's context. Fixed in 3.13.15, 3.14.7 and 3.15.0b3.

CVE-2026-12003 is an uncontrolled search path element flaw (CWE-427) in CPython on Windows, reported by Jake Yamaki (Senior Consultant, Bishop Fox). To let an in-tree build run from its source layout, Python looks for a Modules/setup.local landmark relative to the VPATH build variable. When the landmark is found, Python assumes it is running from a source tree and builds a different default sys.path. On Windows, binaries are built into PCbuild/<arch>, so VPATH is set to ..\.. (the PyVPath MSBuild property in PCbuild/python.props, exposed through Python/sysmodule.c _vpath, Lib/sysconfig and Modules/getpath.py). Bishop Fox traces the dynamic VPATH to a December 2021 commit (99fcf1505218464c489d419d4500f126b6d6dc28), which is why affected releases begin at 3.11.0a3. The code-flow chain it documents is PyVPath (MSBuild) -> VPATH (preprocessor) -> _vpath (sys) -> VPATH (sysconfig) -> BUILD_LANDMARK (getpath.py) -> build_prefix -> stdlib_dir -> sys.path.

With the legacy EXE installer's default all-users location (Bishop Fox gives C:\Program Files\Python<VERSION>), ..\.. resolves to the root of the OS drive. Windows lets ordinary users create folders there. The user creates C:\Modules\Setup.local and a C:\Lib tree (a copy of the stdlib and DLLs plus a site-packages folder). Python then sets build_prefix to C:\ and loads libraries and site-packages from the attacker-controlled C:\Lib. Any later Python launch by another or more privileged account or service runs the planted code. Bishop Fox's PoC has three variants: a malicious .pth file in C:\Lib\site-packages that runs a subprocess (cmd.exe /c whoami && net user), a hijacked json\__init__.py standard-library module, and a .pth variant that spawns PowerShell Start-Process -Verb RunAs to create a local administrator account and add it to the Administrators group (this one needs the elevated user to accept the prompt).

Requirements: Windows, an all-users install at a default location, a writable directory two levels above the install, and a privileged user or service that runs Python after the files are planted. Non-Windows builds do not contain the vulnerable code path. Bishop Fox notes that third-party Python distributions are exposed depending on their install paths, and that the Python installer itself could be affected if a user can make it run through SCCM or a help-desk workflow. The embedded distribution is unaffected because it already uses a ._pth file.

Fix: the VPATH landmark fallback was removed from getpath.py (merged 2026-06-16 as 9e863fab283eddca9c2a8f9d1ee30f4dc243e314 by Steve Dower), and in-tree builds now require pybuilddir.txt, which Windows has generated since 3.11. Backports: GH-151564 (3.15), GH-151565 then GH-151682 (3.14), GH-151566 then GH-151928 (3.13), GH-151567 (3.12), GH-151568 (3.11), plus GH-155642. Only 3.13 and 3.14 get updated legacy installers; earlier branches are source-only fixes (NVD: fixed before 3.11.16, 3.12.14, 3.13.15, 3.14.7, 3.15.0b3). Mitigations: use per-user installs through the Python install manager, create a ._pth file next to python.exe, set PYTHONHOME, pre-create restricted Modules/Lib directories, remove stray C:\Modules\setup.local files, and upgrade.

Severity note: the Python CNA scores this CVSS 4.0 5.3 (MEDIUM, AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H), while Bishop Fox rates it High. The record uses MEDIUM to match the numeric CVSS score. The CISA coordinator SSVC entry on NVD is Exploitation: None, Automatable: No, Technical Impact: Total. SentinelOne reports EPSS 0.14% and no known public exploits, although Bishop Fox publishes PoC commands. NVD status was 'Awaiting Analysis' with no CPE configurations at last check (modified 2026-08-13). In-the-wild exploitation is not reported, and no network IOCs, malware or attribution appear in any source, so BeaconBeagle correlation is not applicable. Bishop Fox's blog timeline dates (04/03, 07/11, 07/16/2026, report date 08/04) conflict with the 2026-06-16 CPython issue and NVD publication, so only the GitHub and NVD dates are used for dated events.

MITRE ATT&CK techniques used in TL-2026-2997

Discovery

T1033 System Owner/User Discovery; T1087.001 Account Discovery: Local Account

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.006 Command and Scripting Interpreter: Python

Persistence

T1098 Account Manipulation; T1136.001 Create Account: Local Account; T1546.018 Event Triggered Execution: Python Startup Hooks

stealth

T1574 Hijack Execution Flow

Affected products and versions in CVE-2026-12003

  • Python Software Foundation — CPython (Windows)
    Vulnerable versions: 3.11.0a3 up to before 3.11.16; 3.12.0-3.12.13; 3.13.0-3.13.14; 3.14.0-3.14.6; 3.15.0a1-3.15.0b2
    Fixed in: 3.13.15; 3.14.7; 3.15.0b3; 3.12.14 (source-only); 3.11.16 (source-only)

Remediation for CVE-2026-12003

Patches

  • Upgrade to Python 3.13.15, 3.14.7, or 3.15.0b3 or later
  • 3.12.14 and the 3.11 branch fix (3.11.16) are source-only; rebuild from patched source
  • Only 3.13 and 3.14 receive updated legacy installers

Immediate actions

  • Inventory Windows hosts with all-users CPython installs from the legacy EXE installer (C:\Program Files\Python3xx)
  • Check for unexpected C:\Modules\Setup.local, C:\Lib, and C:\Lib\site-packages\*.pth on affected hosts and remove any not from a trusted installer
  • Pre-create C:\Modules and C:\Lib as admin-owned, non-writable directories to block landmark planting
  • Restrict standard users from creating directories in the OS drive root
  • Alert on file creation events at the root of system drives for Modules\ or Lib\ directories by non-administrative users

Workarounds

  • Create a ._pth file in the same directory as python.exe
  • Set the PYTHONHOME environment variable
  • Uninstall legacy all-users installs in favour of per-user installs

Longer-term hardening

  • Migrate to per-user installs through the Python install manager
  • Alert on Python processes loading modules or .pth files from outside the install directory
  • Audit scheduled tasks, services, SCCM jobs and help-desk workflows that run python.exe as a privileged account
  • Review third-party Python distributions for the same VPATH behaviour based on their install paths

CVEs associated with CVE-2026-12003

CVE-2026-12003

Weaknesses (CWE) in CVE-2026-12003

CWE-427

Timeline of CVE-2026-12003

  • Per Bishop Fox, a December 2021 CPython commit (99fcf15) made VPATH dynamic, so the Windows build embeds ..\.. as the landmark search path; affected releases begin at 3.11.0a3.
  • NVD publishes CVE-2026-12003 (CWE-427) at 17:16 UTC with a CNA CVSS 4.0 score of 5.3 (MEDIUM); the CISA coordinator SSVC entry reads Exploitation: None, Automatable: No, Technical Impact: Total.
  • Fix PR #151545 merged to main as commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314 by Steve Dower, with backport PRs opened for 3.15 (GH-151564), 3.14 (GH-151565), 3.13 (GH-151566), 3.12 (GH-151567) and 3.11 (GH-151568).
  • CPython issue #151544 (assigned to zooba) and PR #151545 opened; the Python security announcement and oss-security post go out, crediting Jake Yamaki of Bishop Fox. The fix removes the VPATH landmark fallback and requires pybuilddir.txt.
  • SentinelOne's vulnerability database publishes an entry citing EPSS 0.14%, no known public exploits, and detection guidance for Modules\ or Lib\ creation at the drive root by non-admin users.
  • Bishop Fox (Jake Yamaki) publishes its advisory with PowerShell PoC commands for .pth execution, stdlib module hijack and local administrator creation, plus affected/fixed versions, the code-flow trace and mitigations.
  • NVD record last modified at 01:16 UTC; status remains Awaiting Analysis with no CPE configurations. Fixed in 3.13.15, 3.14.7 and 3.15.0b3, with 3.12.14 and 3.11.16 source-only. Later 3.14 and 3.13 backports (GH-151682, GH-151928) supersede the first ones.

Sources cited for CVE-2026-12003

Detection coverage for TL-2026-2997

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2997 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats