Description
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass in enterprise policy enforcement
Action: Patch
AI Analysis

Impact

This vulnerability involves a bypass of security mitigations enforced by Mozilla’s Enterprise Policies component. It arises from a flaw in the policy enforcement logic that allows an attacker to override or eliminate normally protected settings or actions. The weakness corresponds to improper access control, as identified by CWE‑1220 and CWE‑693, and could lead to unauthorized configuration changes, privilege elevation within the application, or compromise of data integrity and confidentiality.

Affected Systems

The affected products are Mozilla Firefox and Mozilla Thunderbird. Versions before the security fixes—Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3—are vulnerable. The issue is present in both the standard and ESR release lines, meaning users on either branch must upgrade.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed active exploits. Based on the description, the attack path most plausibly requires an attacker to be able to influence the enterprise policy engine—most likely through local user interaction or via a compromised account with policy configuration capabilities—rather than through a remote network vector.

Generated by OpenCVE AI on September 21, 2026 at 20:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading to Firefox 156, Firefox ESR 153.3, Thunderbird 156, or Thunderbird 153.3.
  • If an upgrade cannot be performed immediately, disable the Enterprise Policies component or remove policy configuration files to prevent policy enforcement.
  • Continuously monitor system logs for unauthorized policy changes or application behavior that deviates from expected configuration, and enforce strict audit controls.

Generated by OpenCVE AI on September 21, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1220
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Mitigation bypass in the Enterprise Policies component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:48:14.946Z

Reserved: 2026-09-15T12:34:18.265Z

Link: CVE-2026-92057

cve-icon Vulnrichment

Updated: 2026-09-21T17:44:03.208Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:00.073

Modified: 2026-10-05T19:00:04.900

Link: CVE-2026-92057

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:18Z

Links: CVE-2026-92057 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:15:16Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control

  • CWE-693

    Protection Mechanism Failure