CVE-2026-8957

8.8

Mozilla · Firefox, Thunderbird

A privilege escalation vulnerability exists in the Enterprise Policies component of Mozilla Firefox and Thunderbird, potentially allowing full system compromise.

Executive summary

An enterprise policy privilege escalation vulnerability in Mozilla Firefox and Thunderbird poses a critical threat to system security and requires immediate remediation.

Vulnerability

This vulnerability resides in the Enterprise Policies component, allowing an attacker to escalate privileges. It is a network-based attack that requires user interaction and impacts confidentiality, integrity, and availability.

Business impact

With a CVSS score of 8.8, this vulnerability is highly critical. A successful exploit could lead to full system compromise, granting an attacker the ability to perform unauthorized administrative actions, steal sensitive enterprise credentials, or disrupt business operations.

Remediation

Immediate Action: Apply the vendor-provided security updates by upgrading to version 151 or the 140.11 release immediately.

Proactive Monitoring: Review enterprise policy configurations and audit logs for any unauthorized changes or anomalous privilege elevation events.

Compensating Controls: Restrict browser execution environments using Group Policy or Mobile Device Management (MDM) tools to limit the potential impact of a successful privilege escalation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for full system compromise, this CVE must be treated with the highest urgency. Organizations should prioritize the deployment of the patch across all enterprise endpoints to mitigate the risk of privilege escalation.

More Mozilla CVEs