Junglewise Threat Intelligence

CVE-2026-92019: Mozilla Firefox mitigation bypass in Remote Settings Client

CVE-2026-92019 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Firefox's Remote Settings Client component, which manages security and feature configuration updates, contains a mitigation bypass vulnerability. An attacker exploiting this flaw could circumvent browser security controls, potentially enabling malicious content execution or unauthorized system access. This affects Firefox, Firefox ESR, and Thunderbird across multiple versions.

Technical details

CVE-2026-92019 is a mitigation bypass vulnerability in the Remote Settings Client component of Mozilla Firefox. The Remote Settings Client handles secure delivery of configuration and security policy updates to the browser. An attacker can bypass security mitigations protecting this component, potentially allowing interference with critical browser policies and settings. The vulnerability requires network access but does not require user interaction or prior authentication. Patches are available in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 115 before 115.41, 140 before 140.16, 153 before 153.3
  • Mozilla Thunderbird before 156, 140 before 140.16, 153 before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92019 disclosed in Mozilla Security Advisory MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 156, 140.16, 153.3

References

Related threats