« Back to list

CVE-2026-92010

Status: Awaiting AnalysisHigh (8.8)—

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:N/UI:R indica explotación en el cliente con interacción del usuario (T1203). La vulnerabilidad en CanvasWebGL permite ejecución de código (T1059) y escalada de privilegios (T1068) dentro del navegador.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (2)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-92010",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-92010",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-15T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@mozilla.org",
      "affectedData": [
        {
          "vendor": "Mozilla",
          "product": "Firefox",
          "versions": [
            {
              "status": "unaffected",
              "version": "115.41",
              "versionType": "rpm",
              "lessThanOrEqual": "115.*"
            },
            {
              "status": "unaffected",
              "version": "140.16",
              "versionType": "rpm",
              "lessThanOrEqual": "140.*"
            },
            {
              "status": "unaffected",
              "version": "153.3",
              "versionType": "rpm",
              "lessThanOrEqual": "153.*"
            },
            {
              "status": "unaffected",
              "version": "156",
              "versionType": "rpm",
              "lessThanOrEqual": "*"
            }
          ]
        },
        {
          "vendor": "Mozilla",
          "product": "Thunderbird",
          "versions": [
            {
              "status": "unaffected",
              "version": "140.16",
              "versionType": "rpm",
              "lessThanOrEqual": "140.*"
            },
            {
              "status": "unaffected",
              "version": "153.3",
              "versionType": "rpm",
              "lessThanOrEqual": "153.*"
            },
            {
              "status": "unaffected",
              "version": "156",
              "versionType": "rpm",
              "lessThanOrEqual": "*"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-15T13:16:48.740",
  "references": [
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2058067",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-90/",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-91/",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-92/",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-93/",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-94/",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-95/",
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2026-96/",
      "source": "security@mozilla.org"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3."
    }
  ],
  "lastModified": "2026-09-16T19:34:05.910",
  "sourceIdentifier": "security@mozilla.org"
}