CVE-2026-16390

9.1

Mozilla · Firefox and Thunderbird

A mitigation bypass exists in the Enterprise Policies component of Mozilla Firefox and Thunderbird, allowing unauthenticated remote attackers to compromise confidentiality and integrity.

Executive summary

A critical mitigation bypass vulnerability in the Enterprise Policies component of Mozilla Firefox and Thunderbird allows for unauthorized system access and data manipulation.

Vulnerability

The flaw resides in the Enterprise Policies component of the affected applications. It allows an unauthenticated, network-adjacent attacker to bypass established security mitigations, resulting in high impact to confidentiality and integrity.

Business impact

The ability for an unauthenticated attacker to bypass security policies poses a significant risk to organizational data security. Successful exploitation could lead to unauthorized access to sensitive information or the modification of application settings, potentially facilitating further attacks or data exfiltration. Given the CVSS score of 9.1, this vulnerability is classified as critical and requires immediate attention to prevent system compromise.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to version 153 or the ESR 140.13 release immediately.

Proactive Monitoring: Review enterprise environment logs for unusual configuration changes or unauthorized policy modifications occurring within the browser management framework.

Compensating Controls: Restrict access to the Enterprise Policy configuration files and ensure that only authorized administrative accounts can modify browser deployment settings.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity of this vulnerability and its potential for remote exploitation, organizations should prioritize patching as a primary security objective. Failure to apply the vendor-supplied updates leaves the browser environment susceptible to policy manipulation and data theft. Deploy the updated versions across all endpoints as soon as possible to mitigate this risk.

More Mozilla CVEs

Sources

Originally found and disclosed by Souma Ohsawa, per the CVE Program record.