Privilege Escalation in Firefox Security Component by Mozilla
CVE-2026-8970

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8970?

This vulnerability allows attackers to escalate privileges within the Security component of Firefox, potentially enabling unauthorized access to system functions or sensitive data. It is inherent to certain versions of Firefox, which were subsequently patched in Firefox 151 and Firefox ESR 140.11. Users are encouraged to update their browsers immediately to mitigate this risk. For more detailed information, refer to the official Mozilla advisories.

Affected Version(s)

Firefox 140.11

Firefox 151

Thunderbird 140.11

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pakhunov.anton.n
.