← Back to CVE List
CVE-2026-100787NVD
Vulnerability Summary
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVSS v3.1 Base Metrics — Score 9.6 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Mozilla Firefox < 153.4.0
- Mozilla Firefox >= 154.0.0 and < 157.0.0
- Mozilla Thunderbird < 153.4.0
- Mozilla Thunderbird >= 154.0 and < 157.0
- Mozilla Firefox 153.4.0
- Mozilla Firefox 157.0.0
- Mozilla Thunderbird 153.4.0
- Mozilla Thunderbird 157.0