Critical Remote Code Execution Vulnerability in Python-Urwid

Critical Remote Code Execution Vulnerability in Python-Urwid

First seen 26 Aug 2026, 12:22 UTC Linuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability, CVE-2026-9323, was published on July 18, 2026, affecting Rocky Linux 10 and Oracle Linux 8 and 9. The vulnerability allows attackers to exploit insecure session identifiers in the web display module of python-urwid. This flaw can lead to unauthorized remote access, potentially compromising sensitive data and systems. Oracle has released patches for affected versions of python-urwid, specifically addressing the use of cryptographically secure session identifiers. The vulnerability has been acknowledged in multiple advisories, indicating a widespread impact across different Linux distributions. Security professionals are urged to apply the updates promptly to mitigate risks. As of now, there is no confirmed active exploitation reported in the wild, but the severity of the vulnerability necessitates immediate attention.

Key Points: • CVE-2026-9323 poses a critical remote code execution risk in python-urwid. • Affected systems include Rocky Linux 10 and Oracle Linux 8 and 9. • Patches have been released, and immediate application is recommended.

Timeline

2026-07-18
CVE-2026-9323 published
A critical vulnerability in python-urwid was disclosed, affecting multiple Linux distributions.
Linuxsecurity
2026-08-25
Rocky Linux patch released
An update for python-urwid was released to address CVE-2026-9323 for Rocky Linux 10.
Linuxsecurity
2026-08-26
Oracle patches released
Oracle released important updates for python-urwid to fix CVE-2026-9323 for Oracle Linux 8 and 9.
Linuxsecurity
2026-08-26
Oracle Linux 8 advisory published
Oracle Linux 8 issued an advisory regarding the critical remote access vulnerability in python-urwid.
Linuxsecurity