CVE-2026-2803Sensitive Information Exposure in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
0.1%
top 82.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24

Description

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDmozilla/firefox< 148.0
NVDmozilla/thunderbird< 148.0

🔴Vulnerability Details

3
CVEList
Information disclosure, mitigation bypass in the Settings UI component2026-02-24
OSV
CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI component2026-02-24
GHSA
GHSA-7cfj-7vv8-r64h: Information disclosure, mitigation bypass in the Settings UI component2026-02-24

📋Vendor Advisories

4
Red Hat
firefox: thunderbird: Information disclosure, mitigation bypass in the Settings UI component2026-02-24
Debian
CVE-2026-2803: firefox - Information disclosure, mitigation bypass in the Settings UI component. This vul...2026
Mozilla
Mozilla Foundation Security Advisory 2026-13: CVE-2026-2803
Mozilla
Mozilla Foundation Security Advisory 2026-16: CVE-2026-2803

🕵️Threat Intelligence

1
Wiz
CVE-2026-2803 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-2803 — Sensitive Information Exposure | cvebase