CVE-2026-8948
Critical · CVSS 9.1Mozilla Firefox / Thunderbird — Same-origin policy bypass with Cross-Site Scripting (XSS) via DOM Networking component
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-942, CWE-79
Description
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Search profile — drives PoC discovery
Symbols same-origin policyDOMNetworkingSOP bypassCWE-942CWE-79mfsa2026-46mfsa2026-50bugzilla.mozilla.org/show_bug.cgi?id=2038803
Keywords CVE-2026-8948Firefox 151 SOP bypassThunderbird 151 same-origin policyFirefox same-origin policy bypass DOM networkingmfsa2026-46mfsa2026-50Mozilla SOP XSS bypassFirefox XSS DOM networking CVE-2026-8948bug 2038803 mozillaCVE-2026-8948 PoC
Versions: Firefox < 151, Thunderbird < 151
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2038803
- https://www.mozilla.org/security/advisories/mfsa2026-46/
- https://www.mozilla.org/security/advisories/mfsa2026-50/
- https://access.redhat.com/security/cve/CVE-2026-8948
- https://bugzilla.redhat.com/show_bug.cgi?id=2479850
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8948.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-02T00:30:43.000Z