CVE-2026-92073
massFirefox Enterprise Policies Privilege Escalation (Fixed in Firefox 156 & ESR 153.3)
CVE-2026-92073 is a privilege escalation vulnerability (CWE-269, improper privilege management) in the Enterprise Policies component of Mozilla Firefox. Based on the CVSS vector (network attack vector, no privileges required, user interaction required), exploitation likely involves convincing a target user to interact with attacker-controlled content, which then abuses the policies component to run with elevated privileges. A successful attacker gains high impact on confidentiality, integrity, and availability of the browser context and potentially the underlying system. All users running Firefox versions prior to Firefox 156 and Firefox ESR versions prior to 153.3 are affected, with enterprise-managed deployments that rely on policy configuration being particularly relevant. No public proof-of-concept is known, the flaw is not on the CISA KEV catalog, and no exploitation in the wild has been reported.
What to do: Update all Firefox installations to Firefox 156 or Firefox ESR 153.3 immediately, prioritizing enterprise-managed machines that use policies. or Group Policy configuration. Administrators should audit existing policy files and browser configurations for unexpected or unauthorized changes that could indicate tampering. Monitor Mozilla security advisories for follow-up details, since no public PoC exists but disclosure specifics may evolve.
| Mozilla Firefox | All versions prior to Firefox 156 |
| Mozilla Firefox ESR (Extended Support Release) | All versions prior to Firefox ESR 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.