Spoofing Vulnerability in Thunderbird by Mozilla
CVE-2026-3889

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
24 March 2026

What is CVE-2026-3889?

A spoofing vulnerability exists in Thunderbird, which could allow attackers to impersonate legitimate users in email communications. This issue impacts Thunderbird versions earlier than 149 and 140.9, potentially leading to misleading information being sent or received in emails. Users are encouraged to upgrade to the latest versions to mitigate the risk.

Affected Version(s)

Thunderbird < 149

Thunderbird < 140.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eemeli Aro
.