# CVE-2026-12003: CPython on Windows VPATH uncontrolled search path (CWE-427) enables cross-account code execution and privilege escalation

> CPython on Windows (3.11.0a3 through 3.15.0b2) resolves a build-time VPATH of ..\.. to look for a Modules\setup.local landmark outside the install directory. When Python is installed system-wide by the legacy EXE installer, a low-privilege user can create that landmark plus a Lib folder and get code run in another account's context. Fixed in 3.13.15, 3.14.7 and 3.15.0b3.

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2997
- **ID:** TL-2026-2997
- **Severity:** MEDIUM (CVSS 5.3)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-12003

## Description

CVE-2026-12003 is an uncontrolled search path element flaw (CWE-427) in CPython on Windows, reported by Jake Yamaki (Senior Consultant, Bishop Fox). To let an in-tree build run from its source layout, Python looks for a Modules/setup.local landmark relative to the VPATH build variable. When the landmark is found, Python assumes it is running from a source tree and builds a different default sys.path. On Windows, binaries are built into PCbuild/<arch>, so VPATH is set to ..\.. (the PyVPath MSBuild property in PCbuild/python.props, exposed through Python/sysmodule.c _vpath, Lib/sysconfig and Modules/getpath.py). Bishop Fox traces the dynamic VPATH to a December 2021 commit (99fcf1505218464c489d419d4500f126b6d6dc28), which is why affected releases begin at 3.11.0a3. The code-flow chain it documents is PyVPath (MSBuild) -> VPATH (preprocessor) -> _vpath (sys) -> VPATH (sysconfig) -> BUILD_LANDMARK (getpath.py) -> build_prefix -> stdlib_dir -> sys.path.

With the legacy EXE installer's default all-users location (Bishop Fox gives C:\Program Files\Python<VERSION>), ..\.. resolves to the root of the OS drive. Windows lets ordinary users create folders there. The user creates C:\Modules\Setup.local and a C:\Lib tree (a copy of the stdlib and DLLs plus a site-packages folder). Python then sets build_prefix to C:\ and loads libraries and site-packages from the attacker-controlled C:\Lib. Any later Python launch by another or more privileged account or service runs the planted code. Bishop Fox's PoC has three variants: a malicious .pth file in C:\Lib\site-packages that runs a subprocess (cmd.exe /c whoami && net user), a hijacked json\__init__.py standard-library module, and a .pth variant that spawns PowerShell Start-Process -Verb RunAs to create a local administrator account and add it to the Administrators group (this one needs the elevated user to accept the prompt).

Requirements: Windows, an all-users install at a default location, a writable directory two levels above the install, and a privileged user or service that runs Python after the files are planted. Non-Windows builds do not contain the vulnerable code path. Bishop Fox notes that third-party Python distributions are exposed depending on their install paths, and that the Python installer itself could be affected if a user can make it run through SCCM or a help-desk workflow. The embedded distribution is unaffected because it already uses a ._pth file.

Fix: the VPATH landmark fallback was removed from getpath.py (merged 2026-06-16 as 9e863fab283eddca9c2a8f9d1ee30f4dc243e314 by Steve Dower), and in-tree builds now require pybuilddir.txt, which Windows has generated since 3.11. Backports: GH-151564 (3.15), GH-151565 then GH-151682 (3.14), GH-151566 then GH-151928 (3.13), GH-151567 (3.12), GH-151568 (3.11), plus GH-155642. Only 3.13 and 3.14 get updated legacy installers; earlier branches are source-only fixes (NVD: fixed before 3.11.16, 3.12.14, 3.13.15, 3.14.7, 3.15.0b3). Mitigations: use per-user installs through the Python install manager, create a ._pth file next to python.exe, set PYTHONHOME, pre-create restricted Modules/Lib directories, remove stray C:\Modules\setup.local files, and upgrade.

Severity note: the Python CNA scores this CVSS 4.0 5.3 (MEDIUM, AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H), while Bishop Fox rates it High. The record uses MEDIUM to match the numeric CVSS score. The CISA coordinator SSVC entry on NVD is Exploitation: None, Automatable: No, Technical Impact: Total. SentinelOne reports EPSS 0.14% and no known public exploits, although Bishop Fox publishes PoC commands. NVD status was 'Awaiting Analysis' with no CPE configurations at last check (modified 2026-08-13). In-the-wild exploitation is not reported, and no network IOCs, malware or attribution appear in any source, so BeaconBeagle correlation is not applicable. Bishop Fox's blog timeline dates (04/03, 07/11, 07/16/2026, report date 08/04) conflict with the 2026-06-16 CPython issue and NVD publication, so only the GitHub and NVD dates are used for dated events.

## MITRE ATT&CK

- T1574 Hijack Execution Flow
- T1546.018 Event Triggered Execution: Python Startup Hooks
- T1136.001 Create Account: Local Account
- T1098 Account Manipulation
- T1059.006 Command and Scripting Interpreter: Python
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1033 System Owner/User Discovery
- T1087.001 Account Discovery: Local Account

## Sources

- [Bishop Fox: Python Software Foundation | Python 3.11.0a3 to 3.15.0b2](https://bishopfox.com/blog/python-software-foundation-python-3-11-0a3-to-3-15-0b2)
- [CPython issue #151544: In-tree search paths can be enabled without modifying install directory](https://github.com/python/cpython/issues/151544)
- [CPython pull request #151545 (fix, merged as 9e863fa)](https://github.com/python/cpython/pull/151545)
- [NVD: CVE-2026-12003](https://nvd.nist.gov/vuln/detail/CVE-2026-12003)
- [CVE.org record: CVE-2026-12003](https://www.cve.org/CVERecord?id=CVE-2026-12003)
- [Python security-announce thread](https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/)
- [oss-security: CVE-2026-12003](http://www.openwall.com/lists/oss-security/2026/06/16/8)
- [SentinelOne vulnerability database: CVE-2026-12003](https://www.sentinelone.com/vulnerability-database/cve-2026-12003/)
- [INCIBE-CERT: CVE-2026-12003](https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-12003)
- [stack.watch: CVE-2026-12003](https://stack.watch/vuln/CVE-2026-12003/)
- [CPython commit 99fcf15 (December 2021 change that made VPATH dynamic, per Bishop Fox)](https://github.com/python/cpython/commit/99fcf1505218464c489d419d4500f126b6d6dc28)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2997
