Privilege Escalation Vulnerability in Firefox and Firefox ESR
CVE-2026-92055

8.8HIGH

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92055?

A privilege escalation vulnerability exists in the DevTools component of Firefox, potentially allowing unauthorized actions to be executed by a threat actor. This security issue was addressed in updates to Firefox version 156 and Firefox ESR version 153.3, which mitigate the risk to users. It is crucial for users to update to the latest versions to protect against this vulnerability.

Affected Version(s)

Firefox 153.3

Firefox 156

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Finn Westendorf
.