CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.
Other sources
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0887?
CVE-2026-0887 is classified as a moderate severity vulnerability due to its clickjacking and information disclosure implications.
How do I fix CVE-2026-0887?
To fix CVE-2026-0887, update to Firefox version 147 or Firefox ESR version 140.7 or later.
What software is affected by CVE-2026-0887?
CVE-2026-0887 affects Firefox versions prior to 147 and Firefox ESR versions prior to 140.7.
What type of vulnerability is CVE-2026-0887?
CVE-2026-0887 is a clickjacking vulnerability that results in the potential for information disclosure.
Can CVE-2026-0887 be exploited remotely?
Yes, CVE-2026-0887 can be exploited remotely as it allows attackers to deceive users into interacting with malicious content.