Description
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User interface spoofing
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a spoofing issue located in the Document Object Model navigation component of Mozilla Firefox and Thunderbird. Based on the description, it is inferred that a malicious website can manipulate the navigation UI so that a user believes they are interacting with a legitimate, trusted interface, potentially leading them to click links or enter credentials. The weakness is primarily an input handling flaw, corresponding to the CWE classifications for information exposure through spoofing and improper neutralization of input.

Affected Systems

The affected applications are Mozilla Firefox and Mozilla Thunderbird. All versions earlier than Firefox 156 and the ESR 153.3 release, as well as Thunderbird earlier than 156, are impacted. Users on these versions should verify their current build and plan to upgrade to the fixed releases.

Risk and Exploitability

The flaw is client‑side and requires an end‑user to load a crafted page containing malicious DOM content. Based on the description, it is inferred that no explicit execution context or environment is specified, implying the attack requires user interaction with a malicious web page. No public exploit code is cited in the available data, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been observed in known exploitation campaigns. The EPSS score of less than 1% indicates a very low probability of widespread exploitation, yet the potential for phishing or click‑jacking makes it a moderate threat for users who frequently visit untrusted websites.

Generated by OpenCVE AI on September 22, 2026 at 18:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 156 or newer
  • Upgrade Thunderbird to version 156 or newer
  • Upgrade Firefox ESR to version 153.3 or newer

Generated by OpenCVE AI on September 22, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-523
CWE-79

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-523
CWE-79

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Spoofing issue in the DOM: Navigation component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-22T15:27:32.813Z

Reserved: 2026-09-15T12:34:30.492Z

Link: CVE-2026-92069

cve-icon Vulnrichment

Updated: 2026-09-22T15:27:24.903Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:01.620

Modified: 2026-10-05T19:41:14.813

Link: CVE-2026-92069

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:30Z

Links: CVE-2026-92069 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T18:45:18Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')