cbcvebase.
CVE-2026-8952
published 2026-05-19

CVE-2026-8952: Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Affected

4 ranges
VendorProductVersion rangeFixed in
mozillafirefox< Firefox 151Firefox 151
mozillafirefox< 151.0.0151.0.0
mozillathunderbird< Thunderbird 151Thunderbird 151
mozillathunderbird< 151.0.0151.0.0