Junglewise Threat Intelligence

CVE-2026-84136: Mozilla Firefox other issue in DOM Navigation component

CVE-2026-84136 · Severity: medium · CVSS 6.1 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's web page navigation component contains a security defect that could allow unexpected behavior or bypass of protections. The vulnerability affects Firefox's ability to safely handle page navigation operations, potentially impacting the integrity of browsing sessions or web application security boundaries.

Technical details

CVE-2026-84136 is an unspecified ("other") security issue in the DOM Navigation component affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The advisory description does not provide explicit technical details on the vulnerability class, root cause, or attack preconditions. Based on the low impact classification and "other issue" categorization, this likely involves a logic flaw or unintended behavior rather than a memory safety issue. The vulnerability is network-accessible and may require user interaction (e.g., navigation to a malicious page). The issue has been patched in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird before 153.2

Timeline

  • 2026-09-01: disclosed: CVE-2026-84136 publicly disclosed
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, Thunderbird 153.2

References

Related threats