Description
Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized notification display without user permission
Action: Patch
AI Analysis

Impact

The vulnerability allows a web page to bypass the browser’s notification permission mechanism, causing desktop notifications to appear as if the user had explicitly granted permission. The flaw is limited to the notification component and does not provide a pathway for arbitrary code execution or direct access to protected data. The description does not indicate exploitation beyond the premature notification display.

Affected Systems

Mozilla Firefox versions older than 156 and the Firefox ESR 153.3 branch, as well as Mozilla Thunderbird releases older than 156 and the Thunderbird ESR 153.3 release, are impacted. The bug was corrected in Firefox 156/ESR 153.3 and Thunderbird 156/ESR 153.3.

Risk and Exploitability

With a CVSS base score of 6.3 this issue is considered medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The likely attack vector is a remote web page that invokes the Notification API, and based on the description it is inferred that this could trigger the flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no large-scale public exploit has been reported.

Generated by OpenCVE AI on September 21, 2026 at 19:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Firefox 156 or newer, or to ESR 153.3 if using an extended support release.
  • Upgrade Thunderbird to version 156 or newer, or to ESR 153.3 if applicable.
  • If an update is not immediately possible, disable desktop notifications or set the notification permission to "Block" for all origins via the browser settings.
  • Optionally, implement a content‑security‑policy that limits the use of the Notification API to trusted origins only.

Generated by OpenCVE AI on September 21, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Sun, 20 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-358
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Mitigation bypass in the DOM: Notifications component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:26:47.004Z

Reserved: 2026-09-15T12:33:59.605Z

Link: CVE-2026-92039

cve-icon Vulnrichment

Updated: 2026-09-21T17:26:36.357Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:55.300

Modified: 2026-10-05T17:53:41.050

Link: CVE-2026-92039

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:00Z

Links: CVE-2026-92039 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:45:17Z

Weaknesses
  • CWE-358

    Improperly Implemented Security Check for Standard

  • CWE-693

    Protection Mechanism Failure