• PoC PUBLIC

CVE-2026-74939: privilege escalation in Mozilla Firefox

An attacker can escalate privileges in Mozilla Firefox by exploiting a flaw in the DOM navigation component (CVE-2026-74939). The vulnerability enables elevation of privilege against Firefox; affected version ranges are not listed in the provided data. Exploitation requires only network access and user interaction (no prior privileges), and at the time of this report no vendor patch is recorded in the supplied facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00454
CWE
CWE-269
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: public exploit code exists and the flaw requires no prior privileges (CVSS PR:N), so prioritize reducing exposure and monitoring until Mozilla publishes and you deploy a vendor update.

What is CVE-2026-74939?

An attacker can escalate privileges in Mozilla Firefox by exploiting a flaw in the DOM navigation component (CVE-2026-74939). The vulnerability enables elevation of privilege against Firefox; affected version ranges are not listed in the provided data. Exploitation requires only network access and user interaction (no prior privileges), and at the time of this report no vendor patch is recorded in the supplied facts. The weakness is classified as CWE-269 (Improper Privilege Management).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74939 being exploited?

Public exploit code is available.

How to fix CVE-2026-74939

  1. Follow Mozilla vendor guidance and apply official updates as soon as they are released.
  2. Restrict Firefox exposure to untrusted sites and limit network access where possible (block/segment traffic to reduce attack surface).
  3. Enable enhanced logging and monitor endpoints for signs of exploitation and unexpected privilege changes.
  4. Deploy endpoint controls and policy restrictions to limit the impact of a successful privilege escalation.

Frequently asked questions

Is CVE-2026-74939 being actively exploited?

Public exploit code for CVE-2026-74939 is available, but there are no public reports of active exploitation in the supplied data as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-74939?

The supplied facts do not list specific affected Firefox version ranges, so consult Mozilla advisories for authoritative affected-version information.

Is there a patch for CVE-2026-74939?

According to the provided data, no patch is recorded; monitor Mozilla advisories and apply their update when it is published.

Does CVE-2026-74939 require authentication?

No prior privileges are required (CVSS PR:N); exploitation requires user interaction, meaning an attacker typically needs the target to interact with crafted content in Firefox.

References