CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI component
Published Feb 24, 2026
·Updated
Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<148
148
Mozilla Thunderbird<148
148
Mozilla Firefox<148.0
Mozilla Thunderbird<148.0
Event History
Feb 24, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 18, 58128
Event
via FIRST·08:47 AM
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-2757
- CVE-2026-2794
- CVE-2026-2758
- CVE-2026-2759
- CVE-2026-2795
- CVE-2026-2760
- CVE-2026-2761
- CVE-2026-2762
- CVE-2026-2763
- CVE-2026-2764
- CVE-2026-2796
- CVE-2026-2797
- CVE-2026-2765
- CVE-2026-2766
- CVE-2026-2767
- CVE-2026-2768
- CVE-2026-2798
- CVE-2026-2769
- CVE-2026-2799
- CVE-2026-2770
- CVE-2026-2771
- CVE-2026-2772
- CVE-2026-2773
- CVE-2026-2774
- CVE-2026-2775
- CVE-2026-2776
- CVE-2026-2777
- CVE-2026-2778
- CVE-2026-2779
- CVE-2026-2800
- CVE-2026-2780
- CVE-2026-2781
- CVE-2026-2801
- CVE-2026-2782
- CVE-2026-2783
- CVE-2026-2802
- CVE-2026-2803
- CVE-2026-2784
- CVE-2026-2785
- CVE-2026-2804
- CVE-2026-2786
- CVE-2026-2805
- CVE-2026-2787
- CVE-2026-2788
- CVE-2026-2789
- CVE-2026-2806
- CVE-2026-2790
- CVE-2026-2791
- CVE-2026-2807
- CVE-2026-2792
- CVE-2026-2793
Frequently Asked Questions
1
What is the severity of CVE-2026-2803?
CVE-2026-2803 has a severity rating of high, with a CVSS score of 7.5.
2
How do I fix CVE-2026-2803?
To mitigate CVE-2026-2803, users should update to Firefox version 148 or Thunderbird version 148 or later.
3
What type of vulnerability is CVE-2026-2803?
CVE-2026-2803 is classified as an information disclosure vulnerability.
4
What components are affected by CVE-2026-2803?
CVE-2026-2803 affects the Settings UI component in Mozilla Firefox and Mozilla Thunderbird.
5
When was CVE-2026-2803 published?
CVE-2026-2803 was published on February 24, 2026.