CVE-2026-2800 — Authentication Bypass by Spoofing in Mozilla Firefox
Severity
9.8CRITICALNVD
EPSS
0.1%
top 81.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24
Description
Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
4Red Hat
▶
Debian▶
CVE-2026-2800: firefox - Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerabil...↗2026