Description
Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Storage: Cache API component contains a flaw that allows an attacker to bypass internal browser security controls. This oversight undermines the intended isolation of the Cache API, meaning a malicious script could read or manipulate cached data that should otherwise be protected. The weakness is classified both as a missing authentication for a system function (CWE‑807) and as a lack of security awareness for a component (CWE‑693). The CVSS score of 9.1 indicates high severity, reflecting the potential for data compromise if exploited.

Affected Systems

Mozilla Firefox builds prior to version 154, and the ESR releases 140.14 and 153.1, as well as Mozilla Thunderbird builds earlier than version 154, and the ESR releases 140.14 and 153.1 are vulnerable. Users of these builds should consider themselves at risk until the security update is applied.

Risk and Exploitability

The EPSS score is below 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The component is exposed to web content, so the most likely attack vector is via a malicious or compromised web page. No public exploits have been reported, but the bypass of core mitigations could have significant consequences if an attacker succeeds. While exploitation likelihood is low, the potential impact justifies prompt remediation.

Generated by OpenCVE AI on August 21, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Firefox installations to the fixed version 154 or the ESR 140.14/153.1 releases that contain the patch.
  • Upgrade all Thunderbird installations to the fixed version 154 or the ESR 140.14/153.1 releases that contain the patch.
  • If upgrading is not immediately possible, restrict or block access to the Storage: Cache API for untrusted sites through browser policy or content security controls as a temporary measure.

Generated by OpenCVE AI on August 21, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-807
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 18 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Mitigation bypass in the Storage: Cache API component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-21T20:02:58.368Z

Reserved: 2026-08-17T11:58:20.360Z

Link: CVE-2026-74959

cve-icon Vulnrichment

Updated: 2026-08-21T20:02:52.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:33.037

Modified: 2026-08-24T15:52:36.127

Link: CVE-2026-74959

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:31Z

Links: CVE-2026-74959 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:00:14Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision