CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8.
Other sources
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 148 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.33 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 148 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.33 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.8 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 148 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-2757
- CVE-2026-2794
- CVE-2026-2758
- CVE-2026-2759
- CVE-2026-2795
- CVE-2026-2760
- CVE-2026-2761
- CVE-2026-2762
- CVE-2026-2763
- CVE-2026-2764
- CVE-2026-2796
- CVE-2026-2797
- CVE-2026-2765
- CVE-2026-2766
- CVE-2026-2767
- CVE-2026-2768
- CVE-2026-2798
- CVE-2026-2769
- CVE-2026-2799
- CVE-2026-2770
- CVE-2026-2771
- CVE-2026-2772
- CVE-2026-2773
- CVE-2026-2774
- CVE-2026-2775
- CVE-2026-2776
- CVE-2026-2777
- CVE-2026-2778
- CVE-2026-2779
- CVE-2026-2800
- CVE-2026-2780
- CVE-2026-2781
- CVE-2026-2801
- CVE-2026-2782
- CVE-2026-2783
- CVE-2026-2802
- CVE-2026-2803
- CVE-2026-2784
- CVE-2026-2785
- CVE-2026-2804
- CVE-2026-2786
- CVE-2026-2805
- CVE-2026-2787
- CVE-2026-2788
- CVE-2026-2789
- CVE-2026-2806
- CVE-2026-2790
- CVE-2026-2791
- CVE-2026-2807
- CVE-2026-2792
- CVE-2026-2793
Frequently Asked Questions
What is the severity of CVE-2026-2776?
CVE-2026-2776 has been classified as a medium severity vulnerability due to its potential for sandbox escape.
How do I fix CVE-2026-2776?
To fix CVE-2026-2776, upgrade to Mozilla Firefox version 148 or higher, or Firefox ESR version 140.8 or higher.
Which versions of Firefox are affected by CVE-2026-2776?
CVE-2026-2776 affects Firefox versions below 148, Firefox ESR versions below 115.33, and Firefox ESR versions below 140.8.
What component is involved in CVE-2026-2776?
CVE-2026-2776 involves a vulnerability within the Telemetry component of the External Software sandbox.
Is CVE-2026-2776 a widely exploited vulnerability?
As of now, there is no public knowledge indicating that CVE-2026-2776 has been widely exploited in the wild.