Description
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Enterprise Policies component and permits a bypass of the mitigation controls specified by the system. This ability to override or circumvent policy settings could undermine the intended security posture, although the description does not specify any additional capabilities such as code execution. The flaw corresponds to CWE-693, involving insufficient verification of policy authenticity.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected. Any installation of Firefox older than version 153 or ESR 140.13, and any installation of Thunderbird older than version 153 or ESR 140.13, remains vulnerable, as the fix was introduced in those releases.

Risk and Exploitability

The CVSS score of 9.1 indicates a high‑severity flaw, and the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to deliver a malicious policy file or manipulate existing policy configurations to trigger the bypass, but the exact attack vector is not described in the advisory.

Generated by OpenCVE AI on August 4, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 153 or newer, ESR 140.13 or newer; update Thunderbird to version 153 or newer, ESR 140.13 or newer to eliminate the defect.
  • Audit current enterprise policy configurations to ensure that only trusted sources can author monitoring on policy configuration changes and log events for any unauthorized modifications or attempts to enforce nonstandard policies so that potential abuse is detected early.
  • Review the integrity and trust model of policy sources: confirm that only signed or otherwise trusted policy files are accepted, and disable or isolate policy update mechanisms that can receive unsigned or unvalidated input.
  • Enforce integrity checks on policy updates to address the protection mechanism failure identified as CWE-693.

Generated by OpenCVE AI on August 4, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Title Mitigation bypass in the Enterprise Policies component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:54.209Z

Reserved: 2026-07-20T21:57:10.273Z

Link: CVE-2026-16390

cve-icon Vulnrichment

Updated: 2026-07-22T17:18:18.819Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:14.160

Modified: 2026-07-24T15:18:50.477

Link: CVE-2026-16390

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:04Z

Links: CVE-2026-16390 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure