Command Injection in Click - CVE-2026-7246
Published: July 14, 2026
Vulnerability identifier: #VU137405
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-7246
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged user to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation in the click.edit() function. A local privileged user can trick the victim into opening a specially crafted data to pass arbitrary OS commands from an unprivileged account.
Affected software
Click
PowerVC
IBM Fusion HCI
Fedora
openEuler
Anolis OS
Maximo Application Suite - Predict Component
python-click
python3-click
python-click-help
PowerVC
IBM Fusion HCI
Fedora
openEuler
Anolis OS
Maximo Application Suite - Predict Component
python-click
python3-click
python-click-help
How to mitigate CVE-2026-7246
Install updates from vendor's website.
Click - update to 8.3.3
IBM Fusion HCI - update to 2.13.0
Maximo Application Suite - Predict Component - addressed in versions 9.0.17, 9.1.10, 9.2.1
python-click - addressed in versions 8.0.3-2.el9, 8.1.7-7.el10_2, 8.1.7-7.el10_3, 8.1.7-12.fc43
python-click - addressed in versions 8.0.4-2, 8.1.7-2
python3-click - addressed in versions 8.0.4-2, 8.1.7-2
python-click-help - addressed in versions 8.0.4-2, 8.1.7-2
python3-click - update to 8.3.3-1
IBM Fusion HCI - update to 2.13.0
Maximo Application Suite - Predict Component - addressed in versions 9.0.17, 9.1.10, 9.2.1
python-click - addressed in versions 8.0.3-2.el9, 8.1.7-7.el10_2, 8.1.7-7.el10_3, 8.1.7-12.fc43
python-click - addressed in versions 8.0.4-2, 8.1.7-2
python3-click - addressed in versions 8.0.4-2, 8.1.7-2
python-click-help - addressed in versions 8.0.4-2, 8.1.7-2
python3-click - update to 8.3.3-1
External References
- https://github.com/pallets/click/releases/tag/8.3.3
- https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
- https://access.redhat.com/errata/RHSA-2026:24761
- https://access.redhat.com/errata/RHSA-2026:24762
- https://access.redhat.com/security/cve/CVE-2026-7246
- https://bugzilla.redhat.com/show_bug.cgi?id=2464121
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7246.json
Related Security Bulletins
- Command injection in Pallets Click
- IBM Fusion and IBM Fusion HCI update for Pallets Click
- Fedora 43 update for python-click
- Fedora EPEL 10.3 update for python-click
- Fedora EPEL 10.2 update for python-click
- Fedora EPEL 9 update for python-click
- openEuler 24.03 LTS update for python-click
- openEuler 22.03 LTS SP4 update for python-click
- openEuler 24.03 LTS SP3 update for python-click
- openEuler 24.03 LTS SP1 update for python-click
- Anolis OS update for python-click
- Multiple vulnerabilities in IBM Maximo Application Suite - Predict Component
- IBM PowerVC update for Pallets Click