Privilege Escalation in Firefox and Firefox ESR by Mozilla
CVE-2026-8955

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8955?

A vulnerability exists in the DOM: Workers component of Firefox that enables privilege escalation. This security issue could allow malicious actors to exploit the vulnerability for unauthorized access or control. It is crucial for users to upgrade to Firefox version 151 or Firefox ESR version 140.11, where this vulnerability has been addressed.

Affected Version(s)

Firefox 140.11

Firefox 151

Thunderbird 140.11

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lebr0nli
.