Description
Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the networking component of the DOM and is a CWE-284: Improper Access Control flaw that enables an attacker to elevate privileges, potentially allowing execution of privileged network operations or reading of sensitive data normally inaccessible to standard web content. Because it involves improper authorization controls within the DOM, exploitation could compromise confidentiality, integrity, or both, depending on the attacker’s objectives.

Affected Systems

Mozilla Firefox is affected. Versions earlier than Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1 contain the flaw and must be updated.

Risk and Exploitability

The vulnerability is not listed in the CISA KEV catalog, but its nature—privilege escalation—suggests a high impact if exploited. The most likely attack vector is via malicious web content that manipulates the DOM, implying the risk is highest on systems where untrusted web pages are accessed without restrictions.

Generated by OpenCVE AI on August 18, 2026 at 14:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or later, or to the latest ESR release to receive the official fix
  • If an immediate upgrade is not feasible, enforce strict browser security settings such as disabling JavaScript for sensitive domains or applying a Content Security Policy that blocks DOM manipulation by external scripts
  • Consider limiting exposure to untrusted web content by using network isolation or virtualization techniques to isolate browsing sessions from privileged system processes

Generated by OpenCVE AI on August 18, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Privilege escalation in the DOM: Networking component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T15:49:06.078Z

Reserved: 2026-08-17T11:57:27.168Z

Link: CVE-2026-74935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:29.737

Modified: 2026-08-18T14:49:11.260

Link: CVE-2026-74935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses