CVE-2026-74979: pre-auth privilege bypass in Mozilla Firefox

An unauthenticated remote attacker can bypass protections in Firefox's Add-ons Manager and gain full impact on confidentiality, integrity, and availability (CVE-2026-74979). The issue is a mitigation bypass in the browser's add-ons management component that affects Firefox (and related Thunderbird builds), and it requires no privileges or user interaction to exploit over a network according to the published CVSS vector. Specific affected version ranges are not listed in these facts; the vendor has acknowledged the problem but a patch is not recorded here.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00525
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High urgency: this flaw requires no authentication or user interaction, so exposed Firefox installations should be treated as high risk until vendor updates are applied.

What is CVE-2026-74979?

An unauthenticated remote attacker can bypass protections in Firefox's Add-ons Manager and gain full impact on confidentiality, integrity, and availability (CVE-2026-74979). The issue is a mitigation bypass in the browser's add-ons management component that affects Firefox (and related Thunderbird builds), and it requires no privileges or user interaction to exploit over a network according to the published CVSS vector. Specific affected version ranges are not listed in these facts; the vendor has acknowledged the problem but a patch is not recorded here.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74979 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-74979

  1. Limit network exposure of vulnerable Firefox installations and block untrusted network sources.
  2. Apply vendor guidance and install official updates as soon as Mozilla releases them.
  3. Monitor logs and intrusion detection for suspicious activity related to browser add-ons and process launches.
  4. Consider temporary enterprise controls that restrict add-on installation or management until a patch is available.

Frequently asked questions

Is CVE-2026-74979 being actively exploited?

There are no public reports of active exploitation of CVE-2026-74979 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-74979?

These facts note a mitigation bypass in the Add-ons Manager affecting Firefox and related Thunderbird builds, but they do not list specific affected version ranges or fixed versions.

Is there a patch for CVE-2026-74979?

A patch is not recorded in these facts; the vendor has acknowledged the issue but no available fix is listed here.

Does CVE-2026-74979 require authentication?

No — the published CVSS vector indicates no privileges and no user interaction are required, so exploitation can be attempted without authentication or a user click.

References