Threat reportVulnerabilityTL-2026-2997
CVE-2026-12003: CPython on Windows VPATH uncontrolled search path (CWE-427) enables cross-account code execution and privilege escalation
CVE-2026-12003 (TL-2026-2997), also tracked as CPython VPATH in-tree landmark search path hijack, is a medium-severity software vulnerability scored CVSS 5.3, first published 2026-08-05. It has no confirmed attribution, affects Python Software Foundation CPython (Windows), references 1 CVE (CVE-2026-12003), maps to 9 MITRE ATT&CK techniques (T1033, T1059.001, T1059.003), and is covered by 9 detection rules and 10 indicators of compromise.
- CVSS
- 5.3/10Medium
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-2997
- Threat ID
- TL-2026-2997
- Also known as
- CPython VPATH in-tree landmark search path hijack
- Severity
- MEDIUM
- CVSS
- 5.3 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in CVE-2026-12003
Malware and tooling: Python, robocopy
How CVE-2026-12003 works
CPython on Windows (3.11.0a3 through 3.15.0b2) resolves a build-time VPATH of ..\.. to look for a Modules\setup.local landmark outside the install directory. When Python is installed system-wide by the legacy EXE installer, a low-privilege user can create that landmark plus a Lib folder and get code run in another account's context. Fixed in 3.13.15, 3.14.7 and 3.15.0b3.
CVE-2026-12003 is an uncontrolled search path element flaw (CWE-427) in CPython on Windows, reported by Jake Yamaki (Senior Consultant, Bishop Fox). To let an in-tree build run from its source layout, Python looks for a Modules/setup.local landmark relative to the VPATH build variable. When the landmark is found, Python assumes it is running from a source tree and builds a different default sys.path. On Windows, binaries are built into PCbuild/<arch>, so VPATH is set to ..\.. (the PyVPath MSBuild property in PCbuild/python.props, exposed through Python/sysmodule.c _vpath, Lib/sysconfig and Modules/getpath.py). Bishop Fox traces the dynamic VPATH to a December 2021 commit (99fcf1505218464c489d419d4500f126b6d6dc28), which is why affected releases begin at 3.11.0a3. The code-flow chain it documents is PyVPath (MSBuild) -> VPATH (preprocessor) -> _vpath (sys) -> VPATH (sysconfig) -> BUILD_LANDMARK (getpath.py) -> build_prefix -> stdlib_dir -> sys.path.
With the legacy EXE installer's default all-users location (Bishop Fox gives C:\Program Files\Python<VERSION>), ..\.. resolves to the root of the OS drive. Windows lets ordinary users create folders there. The user creates C:\Modules\Setup.local and a C:\Lib tree (a copy of the stdlib and DLLs plus a site-packages folder). Python then sets build_prefix to C:\ and loads libraries and site-packages from the attacker-controlled C:\Lib. Any later Python launch by another or more privileged account or service runs the planted code. Bishop Fox's PoC has three variants: a malicious .pth file in C:\Lib\site-packages that runs a subprocess (cmd.exe /c whoami && net user), a hijacked json\__init__.py standard-library module, and a .pth variant that spawns PowerShell Start-Process -Verb RunAs to create a local administrator account and add it to the Administrators group (this one needs the elevated user to accept the prompt).
Requirements: Windows, an all-users install at a default location, a writable directory two levels above the install, and a privileged user or service that runs Python after the files are planted. Non-Windows builds do not contain the vulnerable code path. Bishop Fox notes that third-party Python distributions are exposed depending on their install paths, and that the Python installer itself could be affected if a user can make it run through SCCM or a help-desk workflow. The embedded distribution is unaffected because it already uses a ._pth file.
Fix: the VPATH landmark fallback was removed from getpath.py (merged 2026-06-16 as 9e863fab283eddca9c2a8f9d1ee30f4dc243e314 by Steve Dower), and in-tree builds now require pybuilddir.txt, which Windows has generated since 3.11. Backports: GH-151564 (3.15), GH-151565 then GH-151682 (3.14), GH-151566 then GH-151928 (3.13), GH-151567 (3.12), GH-151568 (3.11), plus GH-155642. Only 3.13 and 3.14 get updated legacy installers; earlier branches are source-only fixes (NVD: fixed before 3.11.16, 3.12.14, 3.13.15, 3.14.7, 3.15.0b3). Mitigations: use per-user installs through the Python install manager, create a ._pth file next to python.exe, set PYTHONHOME, pre-create restricted Modules/Lib directories, remove stray C:\Modules\setup.local files, and upgrade.
Severity note: the Python CNA scores this CVSS 4.0 5.3 (MEDIUM, AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H), while Bishop Fox rates it High. The record uses MEDIUM to match the numeric CVSS score. The CISA coordinator SSVC entry on NVD is Exploitation: None, Automatable: No, Technical Impact: Total. SentinelOne reports EPSS 0.14% and no known public exploits, although Bishop Fox publishes PoC commands. NVD status was 'Awaiting Analysis' with no CPE configurations at last check (modified 2026-08-13). In-the-wild exploitation is not reported, and no network IOCs, malware or attribution appear in any source, so BeaconBeagle correlation is not applicable. Bishop Fox's blog timeline dates (04/03, 07/11, 07/16/2026, report date 08/04) conflict with the 2026-06-16 CPython issue and NVD publication, so only the GitHub and NVD dates are used for dated events.
MITRE ATT&CK techniques used in TL-2026-2997
Discovery
T1033 System Owner/User Discovery; T1087.001 Account Discovery: Local Account
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.006 Command and Scripting Interpreter: Python
Persistence
T1098 Account Manipulation; T1136.001 Create Account: Local Account; T1546.018 Event Triggered Execution: Python Startup Hooks
stealth
Affected products and versions in CVE-2026-12003
- Python Software Foundation — CPython (Windows)
Vulnerable versions: 3.11.0a3 up to before 3.11.16; 3.12.0-3.12.13; 3.13.0-3.13.14; 3.14.0-3.14.6; 3.15.0a1-3.15.0b2
Fixed in: 3.13.15; 3.14.7; 3.15.0b3; 3.12.14 (source-only); 3.11.16 (source-only)
Remediation for CVE-2026-12003
Patches
- Upgrade to Python 3.13.15, 3.14.7, or 3.15.0b3 or later
- 3.12.14 and the 3.11 branch fix (3.11.16) are source-only; rebuild from patched source
- Only 3.13 and 3.14 receive updated legacy installers
Immediate actions
- Inventory Windows hosts with all-users CPython installs from the legacy EXE installer (C:\Program Files\Python3xx)
- Check for unexpected C:\Modules\Setup.local, C:\Lib, and C:\Lib\site-packages\*.pth on affected hosts and remove any not from a trusted installer
- Pre-create C:\Modules and C:\Lib as admin-owned, non-writable directories to block landmark planting
- Restrict standard users from creating directories in the OS drive root
- Alert on file creation events at the root of system drives for Modules\ or Lib\ directories by non-administrative users
Workarounds
- Create a ._pth file in the same directory as python.exe
- Set the PYTHONHOME environment variable
- Uninstall legacy all-users installs in favour of per-user installs
Longer-term hardening
- Migrate to per-user installs through the Python install manager
- Alert on Python processes loading modules or .pth files from outside the install directory
- Audit scheduled tasks, services, SCCM jobs and help-desk workflows that run python.exe as a privileged account
- Review third-party Python distributions for the same VPATH behaviour based on their install paths
CVEs associated with CVE-2026-12003
Weaknesses (CWE) in CVE-2026-12003
Timeline of CVE-2026-12003
- Per Bishop Fox, a December 2021 CPython commit (99fcf15) made VPATH dynamic, so the Windows build embeds ..\.. as the landmark search path; affected releases begin at 3.11.0a3.
- NVD publishes CVE-2026-12003 (CWE-427) at 17:16 UTC with a CNA CVSS 4.0 score of 5.3 (MEDIUM); the CISA coordinator SSVC entry reads Exploitation: None, Automatable: No, Technical Impact: Total.
- Fix PR #151545 merged to main as commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314 by Steve Dower, with backport PRs opened for 3.15 (GH-151564), 3.14 (GH-151565), 3.13 (GH-151566), 3.12 (GH-151567) and 3.11 (GH-151568).
- CPython issue #151544 (assigned to zooba) and PR #151545 opened; the Python security announcement and oss-security post go out, crediting Jake Yamaki of Bishop Fox. The fix removes the VPATH landmark fallback and requires pybuilddir.txt.
- SentinelOne's vulnerability database publishes an entry citing EPSS 0.14%, no known public exploits, and detection guidance for Modules\ or Lib\ creation at the drive root by non-admin users.
- Bishop Fox (Jake Yamaki) publishes its advisory with PowerShell PoC commands for .pth execution, stdlib module hijack and local administrator creation, plus affected/fixed versions, the code-flow trace and mitigations.
- NVD record last modified at 01:16 UTC; status remains Awaiting Analysis with no CPE configurations. Fixed in 3.13.15, 3.14.7 and 3.15.0b3, with 3.12.14 and 3.11.16 source-only. Later 3.14 and 3.13 backports (GH-151682, GH-151928) supersede the first ones.
Sources cited for CVE-2026-12003
- Bishop Fox: Python Software Foundation | Python 3.11.0a3 to 3.15.0b2
- CPython issue #151544: In-tree search paths can be enabled without modifying install directory
- CPython pull request #151545 (fix, merged as 9e863fa)
- NVD: CVE-2026-12003
- CVE.org record: CVE-2026-12003
- Python security-announce thread
- oss-security: CVE-2026-12003
- SentinelOne vulnerability database: CVE-2026-12003
- INCIBE-CERT: CVE-2026-12003
- stack.watch: CVE-2026-12003
- CPython commit 99fcf15 (December 2021 change that made VPATH dynamic, per Bishop Fox)
Detection coverage for TL-2026-2997
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2997 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.