Description
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape in Profile Backup component
Action: Patch Now
AI Analysis

Impact

The vulnerability in the Profile Backup component can allow a sandbox escape. By bypassing the sandbox, an attacker could gain broader access to files that the component handles, such as backup data and possibly other locally stored configuration. The CVE description does not state that arbitrary code execution or elevated system privileges are achieved, so the impact is limited to the sandbox’s surface area. (The potential for more extensive damage is inferred from typical sandbox escape behavior but is not directly supported by the provided text.)

Affected Systems

Mozilla Firefox and Mozilla Thunderbird, for all releases earlier than version 156. The flaw was addressed in Firefox 156 and Thunderbird 156, so those and later releases are not vulnerable.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog, and the CVSS score of 9.8 classifies it as critical. The data does not disclose a specific attack vector; a likely scenario involves user-initiated backup operations that could be manipulated with untrusted input. Overall, the risk remains high, but remediation is recommended to prevent potential sandbox escape before additional details emerge.

Generated by OpenCVE AI on September 21, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Firefox 156 or later.
  • Upgrade to Thunderbird 156 or later.
  • If an immediate upgrade is not possible, temporarily disable the Profile Backup feature by updating configuration settings or removing existing backup files until the patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-668

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-653
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-668

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156. Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156.
Title Sandbox escape in the Profile Backup component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T18:11:58.229Z

Reserved: 2026-09-15T12:34:27.431Z

Link: CVE-2026-92066

cve-icon Vulnrichment

Updated: 2026-09-21T18:09:35.461Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:01.283

Modified: 2026-10-05T18:46:38.197

Link: CVE-2026-92066

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:27Z

Links: CVE-2026-92066 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:00:07Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization

  • CWE-693

    Protection Mechanism Failure