CVE-2026-12320
published 2026-06-16CVE-2026-12320: Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.18%
7.6th percentile
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 152 | Firefox 152 |
| mozilla | firefox | < 152.0.0 | 152.0.0 |
| mozilla | thunderbird | < Thunderbird 152 | Thunderbird 152 |
| mozilla | thunderbird | < 152.0.0 | 152.0.0 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: thunderbird: Information disclosure in the Password Manager component
vendor_redhat·2026-06-16·CVSS 4.3
CVE-2026-12320 [MEDIUM] CWE-256 firefox: thunderbird: Information disclosure in the Password Manager component
firefox: thunderbird: Information disclosure in the Password Manager component
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Information disclosure in the Password Manager component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/thunderbird-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 10) - Not affected
P
Mozilla
Mozilla Foundation Security Advisory 2026-57: CVE-2026-12320
vendor_mozilla·CVSS 4.3
CVE-2026-12320 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12320
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12320
Product: Firefox
Impact: high
Fixed in: Firefox 152
Mozilla
Mozilla Foundation Security Advisory 2026-60: CVE-2026-12320
vendor_mozilla·CVSS 4.3
CVE-2026-12320 [MEDIUM] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12320
Mozilla Foundation Security Advisory 2026-60
CVE: CVE-2026-12320
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152
VulDB
Mozilla Firefox up to 151 Password Manager information disclosure (Nessus ID 321450)
vuldb·2026-06-18·CVSS 4.3
CVE-2026-12320 [MEDIUM] Mozilla Firefox up to 151 Password Manager information disclosure (Nessus ID 321450)
A vulnerability marked as problematic has been reported in Mozilla Firefox up to 151. This vulnerability affects unknown code of the component Password Manager. Performing a manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-12320. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
Information disclosure in the Password Manager component.
ghsa_unreviewed·2026-06-16
CVE-2026-12320 [MEDIUM] CWE-200 Information disclosure in the Password Manager component.
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152.
No detection rules found.
No public exploits indexed.
2026-06-16
Published