CVE-2026-8957: Privilege escalation in the Enterprise Policies component
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.11 - Upgrade
Upgrade
Mozilla Firefox (Enterprise Policies component)to a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Mozilla Firefox ESR (Enterprise Policies component)to a version that resolves this vulnerability.Fixed in 140.11 - Upgrade
Upgrade
Mozilla Thunderbird (Enterprise Policies component)to a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Mozilla Thunderbird ESR (Enterprise Policies component)to a version that resolves this vulnerability.Fixed in 140.11
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-8945
- CVE-2026-8946
- CVE-2026-8947
- CVE-2026-8948
- CVE-2026-8949
- CVE-2026-8950
- CVE-2026-8951
- CVE-2026-8952
- CVE-2026-8953
- CVE-2026-8954
- CVE-2026-8955
- CVE-2026-8956
- CVE-2026-8957
- CVE-2026-8958
- CVE-2026-8959
- CVE-2026-8960
- CVE-2026-8961
- CVE-2026-8962
- CVE-2026-8963
- CVE-2026-8964
- CVE-2026-8965
- CVE-2026-8966
- CVE-2026-8967
- CVE-2026-8968
- CVE-2026-8969
- CVE-2026-8970
- CVE-2026-8971
- CVE-2026-8972
- CVE-2026-8973
- CVE-2026-8974
- CVE-2026-8975
- CVE-2026-8388
- CVE-2026-8391
- CVE-2026-8401
Frequently Asked Questions
What is the severity of CVE-2026-8957?
CVE-2026-8957 has been classified as a privilege escalation vulnerability, which can potentially allow an attacker to gain elevated permissions.
How do I fix CVE-2026-8957?
To fix CVE-2026-8957, ensure that you update to Firefox 151, Firefox ESR 140.11, Thunderbird 151, or Thunderbird 140.11.
Which products are affected by CVE-2026-8957?
CVE-2026-8957 affects Mozilla Firefox versions up to 151 and Firefox ESR up to 140.11, as well as Thunderbird versions up to 151 and Thunderbird ESR up to 140.11.
Is there a workaround for CVE-2026-8957?
No specific workarounds are suggested for CVE-2026-8957; updating to the patched versions is the recommended action.
What types of vulnerabilities does CVE-2026-8957 include?
CVE-2026-8957 specifically includes privilege escalation vulnerabilities within the Enterprise Policies component.