CVE-2026-2780

CRITICAL WAF: Low
CVSS 9.8 Published: 2026-02-24
CWE-269

Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

WAF Coverage Analysis

Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
mozillafirefoxup to 140.8.0
mozillafirefoxup to 148.0
mozillathunderbirdup to 140.8.0
mozillathunderbirdup to 148.0

References

Back to CVE Database