CVE-2026-8955
published 2026-05-19CVE-2026-8955: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.39%
30.8th percentile
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 151 | Firefox 151 |
| mozilla | firefox | < 140.11.0 | 140.11.0 |
| mozilla | firefox | < 151.0.0 | 151.0.0 |
| mozilla | firefox_esr | < Firefox ESR 140.11 | Firefox ESR 140.11 |
| mozilla | thunderbird | < Thunderbird 140.11 | Thunderbird 140.11 |
| mozilla | thunderbird | < Thunderbird 151 | Thunderbird 151 |
| mozilla | thunderbird | < 140.11 | 140.11 |
| mozilla | thunderbird | < 151.0.0 | 151.0.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47hh-w7m9-q45x: Privilege escalation in the DOM: Workers component
ghsa_unreviewed·2026-05-19
CVE-2026-8955 [MEDIUM] CWE-269 GHSA-47hh-w7m9-q45x: Privilege escalation in the DOM: Workers component
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
VulDB
Mozilla Firefox up to 140.10/150 Workers Remote Code Execution (EUVD-2026-30905)
vuldb·2026-05-19·CVSS 6.5
CVE-2026-8955 [MEDIUM] Mozilla Firefox up to 140.10/150 Workers Remote Code Execution (EUVD-2026-30905)
A vulnerability classified as critical was found in Mozilla Firefox up to 140.10/150. Affected by this vulnerability is an unknown functionality of the component Workers. Executing a manipulation can lead to Remote Code Execution.
This vulnerability is tracked as CVE-2026-8955. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
Red Hat
firefox: Privilege escalation in the DOM: Workers component
vendor_redhat·2026-05-19·CVSS 8.8
CVE-2026-8955 [HIGH] CWE-266 firefox: Privilege escalation in the DOM: Workers component
firefox: Privilege escalation in the DOM: Workers component
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Privilege escalation in the DOM: Workers component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Mozilla
Mozilla Foundation Security Advisory 2026-48: CVE-2026-8955
vendor_mozilla·CVSS 6.5
CVE-2026-8955 [MEDIUM] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8955
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8955
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
Mozilla
Mozilla Foundation Security Advisory 2026-51: CVE-2026-8955
vendor_mozilla·CVSS 6.5
CVE-2026-8955 [MEDIUM] Mozilla Foundation Security Advisory 2026-51: CVE-2026-8955
Mozilla Foundation Security Advisory 2026-51
CVE: CVE-2026-8955
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.11
Mozilla
Mozilla Foundation Security Advisory 2026-46: CVE-2026-8955
vendor_mozilla·CVSS 6.5
CVE-2026-8955 [MEDIUM] Mozilla Foundation Security Advisory 2026-46: CVE-2026-8955
Mozilla Foundation Security Advisory 2026-46
CVE: CVE-2026-8955
Product: Firefox
Impact: high
Fixed in: Firefox 151
Mozilla
Mozilla Foundation Security Advisory 2026-50: CVE-2026-8955
vendor_mozilla·CVSS 6.5
CVE-2026-8955 [MEDIUM] Mozilla Foundation Security Advisory 2026-50: CVE-2026-8955
Mozilla Foundation Security Advisory 2026-50
CVE: CVE-2026-8955
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 151
No detection rules found.
No public exploits indexed.
2026-05-19
Published