Junglewise Threat Intelligence

CVE-2026-92073: Mozilla Firefox privilege escalation in Enterprise Policies

CVE-2026-92073 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox is a widely-used web browser that employees use for business operations. A privilege escalation vulnerability in the Enterprise Policies component could allow an attacker with limited system access to gain elevated permissions, potentially compromising system integrity and enabling further attacks on corporate infrastructure.

Technical details

A privilege escalation vulnerability exists in the Enterprise Policies component of Mozilla Firefox and Thunderbird. The root cause involves improper enforcement or validation of policy controls, allowing an attacker to bypass intended restrictions. The vulnerability requires user interaction (opening a malicious link or file) combined with local system access. Successful exploitation allows an attacker to execute code with elevated privileges, potentially taking full control of the affected system. The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: Security advisory published
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3

References

Related threats