# CPython Windows flaw allows policy bypass

Published: 2026-06-22 · Severity: medium
Canonical: https://vorant.io/reports/c058a7b8-f1db-542b-974b-238c716efcd0/cpython-windows-flaw-allows-policy-bypass

> A vulnerability in CPython for Windows versions 3.11.x through 3.15.x enables attackers to bypass security policies and compromise data confidentiality.

The French CERT (CERT-FR) has disclosed a security vulnerability affecting CPython for Windows across versions 3.11.x to 3.15.x. The flaw, tracked as CVE-2026-12003, allows an attacker to circumvent security policies and compromise the confidentiality of data on affected systems.

The vulnerability represents a risk to organizations running Python applications on Windows platforms within the affected version range. The Python security team has released patches to address this issue, and affected users are advised to apply the latest security updates immediately.

Organizations should prioritize updating their CPython installations on Windows systems, particularly in production environments where Python is used for critical applications or data processing. The advisory emphasizes both the confidentiality impact and the ability to bypass security controls as primary concerns.

## Mentioned in this report

- Vulnerabilities: CVE-2026-12003

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0790

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c058a7b8-f1db-542b-974b-238c716efcd0/cpython-windows-flaw-allows-policy-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
