{"api_version":"1","generated_at":"2026-09-04T00:44:11+00:00","cve":"CVE-2026-84131","urls":{"html":"https://cve.report/CVE-2026-84131","api":"https://cve.report/api/cve/CVE-2026-84131.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-84131","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-84131"},"summary":{"title":"Privilege escalation due to invalid pointer in the Graphics component","description":"Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","state":"PUBLISHED","assigner":"mozilla","published_at":"2026-09-01 13:20:07","updated_at":"2026-09-03 12:53:35"},"problem_types":["CWE-763","CWE-763 CWE-763 Release of Invalid Pointer or Reference"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2060008","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=2060008","refsource":"security@mozilla.org","tags":["Permissions Required"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-88/","name":"https://www.mozilla.org/security/advisories/mfsa2026-88/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-85/","name":"https://www.mozilla.org/security/advisories/mfsa2026-85/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-84/","name":"https://www.mozilla.org/security/advisories/mfsa2026-84/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-87/","name":"https://www.mozilla.org/security/advisories/mfsa2026-87/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-86/","name":"https://www.mozilla.org/security/advisories/mfsa2026-86/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-82/","name":"https://www.mozilla.org/security/advisories/mfsa2026-82/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-83/","name":"https://www.mozilla.org/security/advisories/mfsa2026-83/","refsource":"security@mozilla.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84131","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84131","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 115.40 115.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 140.15 140.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 153.2 153.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Firefox","version":"unaffected 155 * rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Thunderbird","version":"unaffected 140.15 140.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Thunderbird","version":"unaffected 153.2 153.* rpm","platforms":[]},{"source":"CNA","vendor":"Mozilla","product":"Thunderbird","version":"unaffected 155 * rpm","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"navapon","lang":"en"}],"nvd_cpes":[{"cve_year":"2026","cve_id":"84131","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"84131","cve":"CVE-2026-84131","epss":"0.003500000","percentile":"0.279130000","score_date":"2026-09-03","updated_at":"2026-09-04 00:08:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-84131","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-01T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-763","description":"CWE-763 Release of Invalid Pointer or Reference","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-02T03:55:25.128Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"Firefox","vendor":"Mozilla","versions":[{"lessThanOrEqual":"115.*","status":"unaffected","version":"115.40","versionType":"rpm"},{"lessThanOrEqual":"140.*","status":"unaffected","version":"140.15","versionType":"rpm"},{"lessThanOrEqual":"153.*","status":"unaffected","version":"153.2","versionType":"rpm"},{"lessThanOrEqual":"*","status":"unaffected","version":"155","versionType":"rpm"}]},{"product":"Thunderbird","vendor":"Mozilla","versions":[{"lessThanOrEqual":"140.*","status":"unaffected","version":"140.15","versionType":"rpm"},{"lessThanOrEqual":"153.*","status":"unaffected","version":"153.2","versionType":"rpm"},{"lessThanOrEqual":"*","status":"unaffected","version":"155","versionType":"rpm"}]}],"credits":[{"lang":"en","value":"navapon"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2."}],"value":"Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2."}],"providerMetadata":{"dateUpdated":"2026-09-01T21:44:08.906Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2060008"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-82/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-83/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-84/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-85/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-86/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-87/"},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-88/"}],"title":"Privilege escalation due to invalid pointer in the Graphics component"}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2026-84131","datePublished":"2026-09-01T12:18:42.768Z","dateReserved":"2026-09-01T07:25:34.092Z","dateUpdated":"2026-09-02T03:55:25.128Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-01 13:20:07","lastModifiedDate":"2026-09-03 12:53:35","problem_types":["CWE-763","CWE-763 CWE-763 Release of Invalid Pointer or Reference"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-01T00:00:00+00:00","id":"CVE-2026-84131","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"115.40.0","matchCriteriaId":"B84FE134-AC5B-4FF4-9F3C-704D92475BD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"116.0","versionEndExcluding":"140.15.0","matchCriteriaId":"933C120C-6E83-48E4-8002-38E2C93D8E47"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"141.0.0","versionEndExcluding":"153.2.0","matchCriteriaId":"BAC56AB7-FB63-4A76-BFBD-4C0122F2A93C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"154.0.0","versionEndExcluding":"155.0.0","matchCriteriaId":"56769A1A-4A97-4814-8963-24B7AFD7E44F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndExcluding":"140.15.0","matchCriteriaId":"EC44CB46-89FD-40DC-92D1-F865A0521D06"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionStartIncluding":"141.0","versionEndExcluding":"153.2.0","matchCriteriaId":"B217A29A-45B5-407C-9B4B-96CF6EB0838E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionStartIncluding":"154.0","versionEndExcluding":"155.0","matchCriteriaId":"C6AB910B-074A-42F7-A3C7-B7E822011D92"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"84131","Ordinal":"1","Title":"Privilege escalation due to invalid pointer in the Graphics comp","CVE":"CVE-2026-84131","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"84131","Ordinal":"1","NoteData":"Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.","Type":"Description","Title":"Privilege escalation due to invalid pointer in the Graphics comp"}]}}}