Description
Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Remote Settings Client component in Mozilla Firefox contains a flaw that allows an attacker to elevate privileges. When exploited, the vulnerability can give an attacker higher level access than intended, potentially compromising the integrity and confidentiality of the user’s browser session and the system it runs on. The weakness is a form of privilege computation or access control error, enabling unauthorized operations without adequate permission checks.

Affected Systems

Mozilla Firefox is affected, specifically versions 154 and all active ESR releases: Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. Clients running these versions or prior lack the required patch to mitigate the flaw.

Risk and Exploitability

The CVSS score is not provided in the available data, and the EPSS score is unavailable, indicating no published exploitation probability. The vulnerability is not listed in the CISA KEV catalog as of the current information. Based on the component name and typical behavior, it is inferred that the attack vector could be remote, requiring the attacker to supply crafted Remote Settings data. Without a patch, an attacker who successfully exploits the flaw could gain elevated permissions, though the exact conditions and impact scope would depend on the specific system configuration.

Generated by OpenCVE AI on August 18, 2026 at 14:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 154 or later, or install Firefox ESR 115.39, 140.14, or 153.1 to apply the vendor fix.
  • If an immediate update is not feasible, enable automatic updates so that future security patches are applied without manual intervention.
  • Regularly check Mozilla security advisories for any new mitigation recommendations and plan to apply subsequent updates in a timely manner.

Generated by OpenCVE AI on August 18, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Privilege escalation in the Remote Settings Client component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T15:18:15.903Z

Reserved: 2026-08-17T11:57:42.392Z

Link: CVE-2026-74942

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:30.673

Modified: 2026-08-18T14:49:11.260

Link: CVE-2026-74942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T15:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control