Description
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Session Restore component
Action: Patch Immediately
AI Analysis

Impact

The Session Restore component processes stored session data when the application starts. The vulnerability is a privilege‑elevation flaw that allows a local user to gain higher privileges within the running application. It is classified as CWE‑269. The CVE description does not detail the exact mechanism, but it states that the flaw can be exploited until the release of Firefox 156, ESR 153.3, or Thunderbird 156. It is inferred that an attacker could craft a session restore file to trigger the flaw, because session restore files are read during startup.

Affected Systems

All Mozilla Firefox releases prior to version 156, all Firefox ESR releases older than 153.3, and all Mozilla Thunderbird releases older than 156 are affected. Upgrading to Firefox 156 or later, or to Firefox ESR 153.3 or later, and upgrading Thunderbird to 156 or later resolves the issue.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity for privilege escalation. The EPSS score is not available, so exploitation likelihood is unknown. The flaw does not require network access and may be triggered locally; this is inferred from the nature of session restoration. The vulnerability is not listed in the CISA KEV catalog. Because the flaw could allow an attacker to run code with the privileges of the user running the application, it poses a significant risk to users who run the affected products.

Generated by OpenCVE AI on September 16, 2026 at 06:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 156 or newer, or to Firefox ESR 153.3 or newer.
  • Upgrade to Mozilla Thunderbird 156 or newer.
  • If an upgrade cannot be performed immediately, disable the Session Restore feature via the preferences or a policy to prevent state restoration at startup.
  • Remove any manually copied session restore files from user directories until a patch is applied.

Generated by OpenCVE AI on September 16, 2026 at 06:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Privilege escalation in the Session Restore component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T14:24:42.449Z

Reserved: 2026-09-15T12:34:23.385Z

Link: CVE-2026-92062

cve-icon Vulnrichment

Updated: 2026-09-15T13:16:15.954Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:17:00.777

Modified: 2026-09-16T19:34:05.910

Link: CVE-2026-92062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T06:15:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management