Description
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass in enterprise policy enforcement
Action: Patch
AI Analysis

Impact

This vulnerability allows an attacker who can influence the Enterprise Policies component in Mozilla Firefox or Thunderbird to bypass security mitigations that are normally enforced by those policies. The flaw resides in an inadequate check of policy enforcement logic, enabling the attacker to execute actions that would normally be restricted. The impact includes unauthorized configuration changes, potential elevation of privileges, and the ability to tamper with application settings that could compromise data confidentiality and integrity. It aligns with weaknesses such as improper authorization (CWE-285) and improper check of permissions (CWE-640).

Affected Systems

Mozilla Firefox and Thunderbird, versions prior to the fix in Firefox 156, Firefox ESR 153.3, and Thunderbird 156, are affected. The vulnerability is present in the Enterprise Policies component of both browsers.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, so the exact technical severity cannot be determined from the public data. However, because the flaw permits a bypass of enterprise policy controls, it is likely to be considered high risk for organizations that rely on those policies for security. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating that there are no confirmed active exploits at the time of this report. The attacker would need to gain local user access or otherwise influence the policy engine; the attack vector appears to require interaction with the affected application rather than a network‑based intrusion, but the precise prerequisites are not fully documented.

Generated by OpenCVE AI on September 16, 2026 at 04:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest supported versions of Firefox and Thunderbird (Firefox 156, Firefox ESR 153.3, Thunderbird 156).
  • Ensure enterprise policy enforcement is enabled and that no custom policies override core security controls.
  • Review policy logs and audit configuration changes to detect any unauthorized activity.

Generated by OpenCVE AI on September 16, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Mitigation bypass in the Enterprise Policies component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T14:24:41.431Z

Reserved: 2026-09-15T12:34:18.265Z

Link: CVE-2026-92057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:17:00.073

Modified: 2026-09-16T19:34:05.910

Link: CVE-2026-92057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T05:00:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password