8.8
CVE-2026-84128
- EPSS 0.25%
- Veröffentlicht 01.09.2026 12:18:55
- Zuletzt bearbeitet 03.09.2026 12:54:41
- Erkennungen
Privilege escalation in the WebDriver BiDi component
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version < 155.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.16 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://www.mozilla.org/security/advisories/mfsa2026-82/
https://bugzilla.mozilla.org/show_bug.cgi?id=2044280
https://www.mozilla.org/security/advisories/mfsa2026-86/