CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.
Other sources
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0890?
CVE-2026-0890 is classified as a medium severity vulnerability due to its potential to allow spoofing attacks.
How do I fix CVE-2026-0890?
To resolve CVE-2026-0890, upgrade Firefox to version 147 or Firefox ESR to version 140.7 or later.
What products are affected by CVE-2026-0890?
CVE-2026-0890 affects Firefox versions earlier than 147 and Firefox ESR versions earlier than 140.7.
What type of issue is CVE-2026-0890?
CVE-2026-0890 is a spoofing issue related to the Copy & Paste and Drag & Drop components in the DOM.
When was CVE-2026-0890 disclosed?
CVE-2026-0890 was publicly disclosed as part of Mozilla's ongoing security advisories.