Description
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Published: 2026-09-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential confidentiality compromise from cryptographic misuse
Action: Upgrade
AI Analysis

Impact

The flaw is a misuse of cryptographic functions within the Storage: Quota Manager component. This improper handling may allow an attacker to read or otherwise manipulate the data that should be protected by encryption, potentially exposing quota information to unauthorized parties. The public description does not specify a particular exploitation method or whether remote abuse is possible, so the exploitation context remains uncertain.

Affected Systems

All releases of Firefox prior to ESR 153.4 and Firefox 157. The vulnerability is fixed in those specific builds. Users on newer ESR or stable channels should verify the installed version meets or exceeds the fixed build. No specific sub‑versions are listed, so any build older than the mentioned releases may be vulnerable.

Risk and Exploitability

No CVSS score or EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. The lack of known exploitation in the wild and the absence of exploitation details mean the risk level cannot be precisely quantified, but cryptographic misuse poses a notable confidentiality risk. The exact attack surface—whether local or remote—is not detailed in the public information.

Generated by OpenCVE AI on September 30, 2026 at 08:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Firefox ESR 153.4 or Firefox 157 (the releases that contain the fix).
  • If an immediate upgrade is not feasible, consider disabling the Storage Quota feature via about:config or similar controls until a patch is available.
  • Monitor Mozilla’s security advisories for any further patches or guidance on securing cryptographic implementations.
  • Follow secure cryptographic best practices: ensure strong algorithms are used, avoid hard‑coded keys, and validate cryptographic operations to prevent misuse.

Generated by OpenCVE AI on September 30, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-311

Wed, 30 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Title Cryptography misuse in Storage: Quota Manager component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:17.421Z

Reserved: 2026-09-26T19:17:38.515Z

Link: CVE-2026-100798

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T13:17:44.870

Modified: 2026-09-29T21:27:41.130

Link: CVE-2026-100798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T09:00:07Z

Weaknesses
  • CWE-311

    Missing Encryption of Sensitive Data