Junglewise Threat Intelligence

CVE-2026-92030: Mozilla Firefox mitigation bypass in DOM Copy & Paste and Drag & Drop

CVE-2026-92030 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a security mitigation bypass in the DOM component that handles copy, paste, and drag-and-drop operations. This vulnerability could allow an attacker to bypass browser security controls and execute unintended operations through these user interactions, potentially compromising user data or browser security boundaries.

Technical details

CVE-2026-92030 is a mitigation bypass vulnerability in Mozilla Firefox and Thunderbird's DOM: Copy & Paste and Drag & Drop component. The vulnerability allows an attacker to circumvent security mitigations that protect against unauthorized copy, paste, and drag-and-drop operations. The attack is network-reachable and requires no special authentication, though user interaction with the affected DOM operations may be required. Exploitation could lead to unauthorized data access or modification. The vulnerability has been fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox below 156
  • Mozilla Firefox ESR below 140.16 and 153.3
  • Mozilla Thunderbird below 156
  • Mozilla Thunderbird below 140.16 and 153.3

Timeline

  • 2026-09-15: disclosed: Vulnerability published and advisory released
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3

References

Related threats