CVE-2026-74939: Privilege escalation in the DOM: Navigation component
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.39 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 154 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.39 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.14 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 153.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-74934
- CVE-2026-74935
- CVE-2026-74936
- CVE-2026-74939
- CVE-2026-74940
- CVE-2026-74941
- CVE-2026-74942
- CVE-2026-74943
- CVE-2026-74944
- CVE-2026-74945
- CVE-2026-74946
- CVE-2026-74948
- CVE-2026-74949
- CVE-2026-74953
- CVE-2026-74957
- CVE-2026-74959
- CVE-2026-74960
- CVE-2026-74962
- CVE-2026-74963
- CVE-2026-74964
- CVE-2026-74965
- CVE-2026-74967
- CVE-2026-74969
- CVE-2026-74971
- CVE-2026-74972
- CVE-2026-74973
- CVE-2026-74974
- CVE-2026-74976
- CVE-2026-74983
- CVE-2026-74987
- CVE-2026-74990
- CVE-2026-75874
- CVE-2026-74937
- CVE-2026-74938
- CVE-2026-74947
- CVE-2026-74950
- CVE-2026-74951
- CVE-2026-74952
- CVE-2026-74954
- CVE-2026-74955
- CVE-2026-74956
- CVE-2026-74958
- CVE-2026-74961
- CVE-2026-74966
- CVE-2026-74968
- CVE-2026-74970
- CVE-2026-74975
- CVE-2026-74977
- CVE-2026-74978
- CVE-2026-74979
- CVE-2026-74980
- CVE-2026-74981
- CVE-2026-74982
- CVE-2026-74984
- CVE-2026-74985
- CVE-2026-74986
- CVE-2026-74988
- CVE-2026-74989
Frequently Asked Questions
Which Firefox releases contain the fix?
Firefox installations earlier than version 154 are affected. Firefox ESR installations should be updated to 115.39, 140.14, or 153.1, depending on the ESR release in use.
What should administrators do if they are assessing exposure?
The provided information identifies this as a privilege-escalation issue in Firefox's DOM Navigation component, but does not state prerequisites, exploitation conditions, or temporary mitigations. Updating to a fixed Firefox or Firefox ESR release is the documented remediation.