CVE-2026-8094

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

11 May 2026, 15:12

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2035939 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2035939 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-41/ - () https://www.mozilla.org/security/advisories/mfsa2026-41/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-44/ - () https://www.mozilla.org/security/advisories/mfsa2026-44/ - Vendor Advisory
First Time Mozilla thunderbird
Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

08 May 2026, 23:16

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

08 May 2026, 13:16

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-44/ -
Summary (en) Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2. (en) Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

07 May 2026, 14:08

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 13:16

Updated : 2026-05-11 15:12


NVD link : CVE-2026-8094

Mitre link : CVE-2026-8094

CVE.ORG link : CVE-2026-8094


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')