Junglewise Threat Intelligence

CVE-2026-8957: Mozilla Firefox privilege escalation in Enterprise Policies

CVE-2026-8957 · Severity: info · CVSS 6.1 · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A privilege escalation vulnerability exists in the Enterprise Policies component of Mozilla Firefox. This component is used by IT administrators to manage browser settings and security policies across an organization. An exploit could allow a user or process with limited permissions to bypass intended restrictions and gain elevated access on the system.

Technical details

A privilege escalation vulnerability was identified in the Enterprise Policies component of Mozilla Firefox. The flaw resides in how the browser handles or enforces administrative policies, potentially allowing a local attacker to bypass policy-based restrictions to gain higher-level permissions. While specific technical root causes are restricted in the associated bug reports, the vulnerability is classified as a privilege escalation with moderate impact. The issue is resolved in Firefox 151 and Firefox ESR 140.11.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched
  • 2026-05-19: advisory

References

Related threats