Description
Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an information disclosure flaw within the Networking: JAR component of Mozilla Firefox. An attacker can cause the browser to reveal sensitive data that it would otherwise keep private, such as authentication credentials or local files. The issue is aligned with CWE‑200, Information Exposure, and can compromise confidentiality when exploited.

Affected Systems

This flaw affects Mozilla Firefox installations on all operating systems where the Networking: JAR component is enabled. The fixes are available in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Systems running earlier releases of these branches are vulnerable.

Risk and Exploitability

EPSS data is not published for this issue and it is not listed in the CISA KEV catalog, indicating no current known exploitation campaign. However, because the flaw allows information to escape over the network, the likely attack vector is indirect remote exploitation via user interaction with a malicious JAR resource. The CVSS score is not supplied, but the presence of a patch in multiple release lines and the lack of detection in KEV suggest the risk is moderate to high for systems that remain unpatched. Immediate attention is advised to upgrade or apply the fix.

Generated by OpenCVE AI on September 29, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to one of the patched Firefox versions (ESR 153.4, ESR 115.42, ESR 140.17, or Firefox 157) or a newer release.
  • If an upgrade cannot be performed immediately, isolate affected systems from untrusted network traffic that could trigger the JAR component or block traffic to known JAR endpoints.
  • Monitor for anomalous data exposure and ensure future security updates are applied as soon as they become available.

Generated by OpenCVE AI on September 29, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Information disclosure in the Networking: JAR component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T15:09:46.478Z

Reserved: 2026-09-26T19:15:22.826Z

Link: CVE-2026-100766

cve-icon Vulnrichment

Updated: 2026-09-29T15:09:42.992Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.837

Modified: 2026-09-29T16:17:05.343

Link: CVE-2026-100766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:00:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor