Description
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Session Restore component
Action: Patch Immediately
AI Analysis

Impact

The Session Restore component processes stored session data when the application starts. The vulnerability is a privilege‑elevation flaw that allows a local user to gain higher privileges within the running application. It is classified as CWE‑269. The CVE description does not detail the exact mechanism, but it states that the flaw can be exploited until the release of Firefox 156, ESR 153.3, or Thunderbird 156. It is inferred that an attacker could craft a session restore file to trigger the flaw, because session restore files are read during startup.

Affected Systems

All Mozilla Firefox releases prior to version 156, all Firefox ESR releases older than 153.3, and all Mozilla Thunderbird releases older than 156 are affected. Upgrading to Firefox 156 or later, or to Firefox ESR 153.3 or later, and upgrading Thunderbird to 156 or later resolves the issue.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity for privilege escalation. The EPSS score of < 1% indicates a very low exploitation probability. The flaw does not require network access and may be triggered locally; this is inferred from the nature of session restoration. The vulnerability is not listed in the CISA KEV catalog. Because the flaw could allow an attacker to run code with the privileges of the user running the application, it poses a significant risk to users who run the affected products.

Generated by OpenCVE AI on September 20, 2026 at 17:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 156 or newer, or to Firefox ESR 153.3 or newer.
  • Upgrade to Mozilla Thunderbird 156 or newer.
  • If an upgrade cannot be performed immediately, disable the Session Restore feature via the preferences or a policy to prevent state restoration at startup.
  • Remove any manually copied session restore files from user directories until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 17 Sep 2026 12:15:00 +0000


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Privilege escalation in the Session Restore component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T14:24:42.449Z

Reserved: 2026-09-15T12:34:23.385Z

Link: CVE-2026-92062

cve-icon Vulnrichment

Updated: 2026-09-15T13:16:15.954Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:00.777

Modified: 2026-10-05T18:58:14.363

Link: CVE-2026-92062

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:23Z

Links: CVE-2026-92062 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management