Red Hat disclosed CVE-2026-9323, an Important flaw in the urwid web display backend that lets attackers predict or obtain urwid_id session identifiers and hijack active terminal sessions. The vulnerable code in urwid/display/web.py generated session IDs in Screen.start() with Python’s non-cryptographic Mersenne Twister PRNG, a weakness aligned with CWE-1241 for predictable random number generation. The same identifier could also be exposed locally as a FIFO filename in the world-listable /tmp directory, increasing the chance that an attacker could recover a valid session token.

See affected versions and whether adversaries are exploiting it.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:60353 to remediate CVE-2026-9323 in python-urwid on RHEL 10, including RHEL EUS 10.0. The Important-rated update addresses predictable Urwid session IDs that may permit remote code execution and information disclosure.
AlmaLinux published security advisory ALSA-2026:58561 to address CVE-2026-9323 in python3-urwid across AlmaLinux 10 repositories. The associated Nessus plugin reports no known public exploits and recommends applying the advisory's updated packages.
AlmaLinux 9 issued security advisory ALSA-2026:58952 to remediate CVE-2026-9323 in python3-urwid across affected repositories. The associated Nessus plugin states that the patch was published on 2026-08-24 and that no known exploits were available.
AlmaLinux 8 published security advisory ALSA-2026:58562 to address CVE-2026-9323 in the python3-urwid package across multiple repositories. A Tenable Nessus plugin published afterward references the advisory, notes the patch publication date as 2026-08-24, and states no known exploits were available.
Red Hat published advisory RHSA-2026:59198 to address CVE-2026-9323 in python-urwid on RHEL 8, including RHEL AUS 8.6 coverage. A Nessus plugin published afterward references the patch, notes Important severity, and recommends updating affected packages based on self-reported version detection.
Oracle Linux 10 published security advisory ELSA-2026-58561 to address CVE-2026-9323 in the python3-urwid package for the BaseOS channel. A Nessus plugin published the same day references the advisory and states no known exploits were available.
Rocky Linux 8 published security advisory RLSA-2026:58562 to address CVE-2026-9323 in python-urwid packages. The associated Nessus plugin states the patch was published on 2026-08-24 and that no known exploits were available at that time.
Red Hat published advisory RHSA-2026:58562 for Red Hat Enterprise Linux 8 to address CVE-2026-9323 in python-urwid. A Tenable Nessus plugin published the same day references the patch, notes Important severity, and recommends updating affected packages based on installed version detection.
Red Hat published advisory RHSA-2026:58955 for RHEL 9.6 Extended Update Support to address CVE-2026-9323 in python-urwid. A Tenable Nessus plugin published the same day references the patch and recommends updating affected packages based on installed version detection.
Red Hat published advisory RHSA-2026:58954 for RHEL 9 to address CVE-2026-9323 in python-urwid. A Tenable Nessus plugin published the same day references the patch, notes Important severity, and recommends updating affected packages based on version detection.
Red Hat published advisory RHSA-2026:58953 for Red Hat Enterprise Linux 9.4 E4S to address CVE-2026-9323 in python-urwid. A Tenable Nessus plugin published afterward references the patch, notes Important severity, and recommends updating affected packages based on self-reported version detection.
Red Hat published advisory RHSA-2026:58952 for RHEL 9 and RHEL EUS 9.8 to address CVE-2026-9323 in python-urwid. A Nessus plugin published the same day references the patch and recommends updating affected python-urwid packages.
Red Hat published advisory RHSA-2026:58561 for RHEL 10 to address CVE-2026-9323 in python-urwid. A Tenable Nessus plugin published the same day references the patch and recommends updating affected packages.
Red Hat issued security advisory RHSA-2026:57638 and released updated python-urwid packages for RHEL 8.4 support channels to remediate CVE-2026-9323. The advisory covers Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On on x86_64.
CVE-2026-9323 was published for a vulnerability in Urwid in which predictable session IDs can enable remote code execution and information disclosure. The issue is associated with CWE-1241.
Red Hat's Bugzilla entry 2502072 documented that Urwid's web backend generated session identifiers with Python's Mersenne Twister and reused them as world-listable FIFO names in /tmp, enabling session prediction or discovery. The entry described impacts including screen viewing, keystroke injection, session termination, crashes, and possible code execution in shell sessions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.