Description
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates in Firefox's request handling component, allowing an attacker to bypass established access controls and gain elevated privileges on the victim machine. By exploiting improper validation of incoming requests, an attacker can execute privileged code, potentially compromising the entire system. This flaw is classified as a privilege escalation weakness.

Affected Systems

Affected users are those running Mozilla Firefox versions prior to 154 and the ESR line before 153.1. All users of the legacy Firefox distribution, especially those who have not applied recent security updates, remain vulnerable.

Risk and Exploitability

There is no EPSS score available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating limited public evidence of active exploitation. The CVSS score is not provided, but the nature of the flaw suggests a high severity. The likely attack path is through a specially crafted request that a user might process in Firefox, such as visiting a malicious site or interacting with compromised network traffic. Depending on the victim’s user permissions, the attacker may gain local privilege escalation.

Generated by OpenCVE AI on August 18, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 154 or later, or ESR 153.1 or later, which contain the official fix for this vulnerability.
  • If immediate upgrading is not possible, restrict the browser’s ability to process requests from untrusted origins by applying security policies or disabling the affected component.
  • Monitor users for suspicious activity that may indicate privilege escalation attempts and enforce the principle of least privilege for accounts that run the browser.

Generated by OpenCVE AI on August 18, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Privilege escalation in the Request Handling component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:37.460Z

Reserved: 2026-08-17T11:58:10.442Z

Link: CVE-2026-74955

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:32.493

Modified: 2026-08-18T13:17:32.493

Link: CVE-2026-74955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses