CVE-2026-12320: Information disclosure in the Password Manager component
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 152 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 152
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-12289
- CVE-2026-12290
- CVE-2026-12291
- CVE-2026-12292
- CVE-2026-12293
- CVE-2026-12294
- CVE-2026-12295
- CVE-2026-12296
- CVE-2026-12297
- CVE-2026-12298
- CVE-2026-12299
- CVE-2026-12300
- CVE-2026-12301
- CVE-2026-12302
- CVE-2026-12303
- CVE-2026-12304
- CVE-2026-12305
- CVE-2026-12306
- CVE-2026-12307
- CVE-2026-12308
- CVE-2026-12309
- CVE-2026-12310
- CVE-2026-12311
- CVE-2026-12312
- CVE-2026-12313
- CVE-2026-12314
- CVE-2026-12315
- CVE-2026-12316
- CVE-2026-12317
- CVE-2026-12318
- CVE-2026-12319
- CVE-2026-12320
- CVE-2026-12321
- CVE-2026-12322
- CVE-2026-12323
- CVE-2026-12324
- CVE-2026-12325
- CVE-2026-12326
- CVE-2026-12327
- CVE-2026-12328
Frequently Asked Questions
What type of vulnerability is CVE-2026-12320?
CVE-2026-12320 is classified as an information disclosure vulnerability in the Password Manager component.
What is the severity level of CVE-2026-12320?
CVE-2026-12320 has a medium severity rating of 4.3 based on the CVSS 3.1 metrics.
How do I fix CVE-2026-12320?
To fix CVE-2026-12320, update your Mozilla Firefox or Thunderbird to version 152 or later.
Which software is affected by CVE-2026-12320?
CVE-2026-12320 affects Mozilla Firefox and Mozilla Thunderbird.
When was CVE-2026-12320 published?
CVE-2026-12320 was published on June 16, 2026.