Junglewise Threat Intelligence

CVE-2026-16390: Mozilla Firefox mitigation bypass in Enterprise Policies

CVE-2026-16390 · Severity: info · CVSS 5.4 · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the Enterprise Policies component of Mozilla Firefox could allow security restrictions set by IT administrators to be bypassed. This component is used by organizations to manage browser settings and enforce security rules across their workforce. An exploit could allow a user or malicious site to circumvent these corporate security controls, potentially leading to unauthorized configuration changes.

Technical details

A mitigation bypass vulnerability was identified in the Enterprise Policies component of Mozilla Firefox. The flaw resides in how the browser handles or enforces administrative policies, allowing an attacker or a local user to bypass intended security restrictions. While specific technical details are restricted in the associated Bugzilla report, the vulnerability is classified as a 'mitigation bypass' with moderate impact. The issue is resolved in Firefox 153 and Firefox ESR 140.13 by improving the enforcement mechanisms within the Enterprise Policies component.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 140.13

Timeline

  • 2026-07-21: advisory: Mozilla Foundation Security Advisory published
  • 2026-07-21: patched: Fixed in Firefox 153 and Firefox ESR 140.13

References

Related threats