CVE-2026-8401

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

History

19 May 2026, 18:16

Type Values Removed Values Added
Summary (en) Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, and Firefox ESR 140.11. (en) Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-51/ -

19 May 2026, 14:16

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2026-47/ -
  • () https://www.mozilla.org/security/advisories/mfsa2026-48/ -
Summary (en) Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3. (en) Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, and Firefox ESR 140.11.

15 May 2026, 20:05

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2038679 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2038679 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-45/ - () https://www.mozilla.org/security/advisories/mfsa2026-45/ - Vendor Advisory
First Time Mozilla
Mozilla firefox

14 May 2026, 20:17

Type Values Removed Values Added
CWE CWE-693
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

12 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 15:16

Updated : 2026-05-19 18:16


NVD link : CVE-2026-8401

Mitre link : CVE-2026-8401

CVE.ORG link : CVE-2026-8401


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-693

Protection Mechanism Failure