Description
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Enterprise Policies component in Firefox and Thunderbird exposes a local privilege escalation flaw. A local attacker can use the component to elevate privileges within the application, which may allow them to perform operations reserved for privileged users. The issue is fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected Systems

Mozilla Firefox versions before 154 and Firefox ESR before 153.1, as well as Mozilla Thunderbird versions before 154 and Thunderbird ESR before 153.1, are impacted. All installations that have not applied the latest security updates are susceptible.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low probability of exploitation at scale, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is 9.8, so the risk is significant for any local user. The likely attack vector is local, requiring the attacker to already have accessed the user account or gained local code execution. Exploitation would allow the attacker to perform actions or modify settings that should be restricted to privileged users.

Generated by OpenCVE AI on August 21, 2026 at 17:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to version 154 or Firefox ESR 153.1, and update Thunderbird to version 154 or Thunderbird ESR 153.1, which contain the fix.
  • If updating is not immediately possible, disable the Enterprise Policies component or restrict its configuration to limit elevated operations.
  • After patching or disabling the component, configure strict policy enforcement and continuously monitor for any unauthorized changes to policies or elevated privileges.

Generated by OpenCVE AI on August 21, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 00:15:00 +0000


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Privilege escalation in the Enterprise Policies component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-21T03:55:23.242Z

Reserved: 2026-08-17T11:59:18.049Z

Link: CVE-2026-74985

cve-icon Vulnrichment

Updated: 2026-08-20T15:42:27.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:40.317

Modified: 2026-08-25T15:39:27.060

Link: CVE-2026-74985

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-18T12:23:41Z

Links: CVE-2026-74985 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management