CVE-2026-8094

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

30 Jun 2026, 03:21

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:19160 -
  • () https://access.redhat.com/errata/RHSA-2026:20566 -
  • () https://access.redhat.com/errata/RHSA-2026:20574 -
  • () https://access.redhat.com/errata/RHSA-2026:24508 -
  • () https://access.redhat.com/errata/RHSA-2026:24509 -
  • () https://access.redhat.com/errata/RHSA-2026:24510 -
  • () https://access.redhat.com/errata/RHSA-2026:24511 -
  • () https://access.redhat.com/errata/RHSA-2026:24516 -
  • () https://access.redhat.com/errata/RHSA-2026:24755 -
  • () https://access.redhat.com/errata/RHSA-2026:24983 -
  • () https://access.redhat.com/errata/RHSA-2026:25015 -
  • () https://access.redhat.com/security/cve/CVE-2026-8094 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2467706 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8094.json -

11 May 2026, 15:12

Type Values Removed Values Added
First Time Mozilla thunderbird
Mozilla
Mozilla firefox
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2035939 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2035939 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-41/ - () https://www.mozilla.org/security/advisories/mfsa2026-41/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-44/ - () https://www.mozilla.org/security/advisories/mfsa2026-44/ - Vendor Advisory

08 May 2026, 23:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

08 May 2026, 13:16

Type Values Removed Values Added
Summary (en) Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2. (en) Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-44/ -

07 May 2026, 14:08

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 13:16

Updated : 2026-07-15 01:17


NVD link : CVE-2026-8094

Mitre link : CVE-2026-8094

CVE.ORG link : CVE-2026-8094


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')