CVE-2026-2800Authentication Bypass by Spoofing in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
0.1%
top 81.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24

Description

Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDmozilla/firefox< 148.0
NVDmozilla/thunderbird< 148.0

🔴Vulnerability Details

3
OSV
CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android2026-02-24
CVEList
Spoofing issue in the WebAuthn component in Firefox for Android2026-02-24
GHSA
GHSA-wcpx-2xqg-ff43: Spoofing issue in the WebAuthn component in Firefox for Android2026-02-24

📋Vendor Advisories

4
Red Hat
firefox: thunderbird: Spoofing issue in the WebAuthn component in Firefox for Android2026-02-24
Debian
CVE-2026-2800: firefox - Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerabil...2026
Mozilla
Mozilla Foundation Security Advisory 2026-16: CVE-2026-2800
Mozilla
Mozilla Foundation Security Advisory 2026-13: CVE-2026-2800

🕵️Threat Intelligence

1
Wiz
CVE-2026-2800 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-2800 — Authentication Bypass by Spoofing | cvebase