VDB
CVE-2026-92073
CVE-2026-92073
PUBLISHED
CVSS 8.8 HIGH
Reported by mozilla · Published September 15, 2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 153.3, 156 |
| Mozilla | Thunderbird | 153.3, 156 |
| Mozilla | Thunderbird | 156, 153.3, 156 |
| Mozilla | Firefox | 153.3, 156, 153.3 |
Timeline
- Sep 15, 2026 Coalition ESS Score
- Sep 15, 2026 CVE Published
- Sep 16, 2026 EPSS Score
- Sep 16, 2026 CVE Updated
- Sep 18, 2026 EPSS Score