CVE-2026-2780

CRITICAL WAF: Low
CVSS 9.8 Published: 2026-02-24
CWE-269

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

WAF Coverage Analysis

Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
mozillafirefoxup to 140.8.0
mozillafirefoxup to 148.0
mozillathunderbirdup to 140.8.0
mozillathunderbirdup to 148.0

References

Back to CVE Database