Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-74985: Firefox Privilege Escalation Risk in Enterprise Policies
CVE-2026-74985 · published 1 month ago
Summary
Firefox's Enterprise Policies component has a security weakness. This weakness could allow an attacker to gain more access than they should. To stay safe, update to the latest version of Firefox, specifically version 154 or later, or Firefox ESR 153.1 or later.
What to do
- Update mozilla firefox to version 153.1.0 or later.
- Update mozilla thunderbird to version 153.1.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:22.04:LTS | canonical | mozjs91 | All versions |
| Ubuntu:22.04:LTS | canonical | mozjs102 | All versions |
| – | mozilla | firefox | < 153.1.0 |
| – | mozilla | thunderbird | < 153.1.0 |
| Ubuntu:22.04:LTS | canonical | mozjs78 | All versions |
| Ubuntu:18.04:LTS | canonical | mozjs52 | All versions |
| Ubuntu:18.04:LTS | canonical | mozjs38 | All versions |
| Ubuntu:20.04:LTS | canonical | mozjs68 | All versions |
| Ubuntu:20.04:LTS | canonical | mozjs52 | All versions |
| Ubuntu:22.04:LTS | canonical | thunderbird | All versions |
| Ubuntu:24.04:LTS | canonical | mozjs102 | All versions |
| Ubuntu:24.04:LTS | canonical | mozjs115 | All versions |
Original advisory text
Privilege escalation in the Enterprise Policies component
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059825 Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2026-74/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-77/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-78/ Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-74985 Third Party Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74985 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-74985 Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-80/ Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published18 Aug 2026
Updated27 Sep 2026
First seen18 Aug 2026
Track software like this
Free during beta