PatchSiren cyber security CVE debrief
CVE-2026-8972 Mozilla CVE debrief
CVE-2026-8972 is a Mozilla privilege-escalation vulnerability in the WebRTC: Audio/Video component. NVD rates it 8.8 High with a network attack vector, low attack complexity, no attacker privileges, and user interaction required. Mozilla’s advisory references indicate the issue was fixed in Firefox 151 and Thunderbird 151, and NVD lists affected versions as those before 151.0.0.
- Vendor
- Mozilla
- Product
- Firefox
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-23
Who should care
Security teams and endpoint admins running Mozilla Firefox or Thunderbird should prioritize this if any systems remain on versions earlier than 151.0.0. It is especially relevant where browsers or mail clients are broadly deployed and where WebRTC features are in use.
Technical summary
The available source data describes a privilege-escalation flaw in Firefox and Thunderbird’s WebRTC: Audio/Video component. NVD maps the issue to CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H and associates CWE-269. The vendor references point to Mozilla Bugzilla tracking and Mozilla security advisories, and the CVE record says the issue was fixed in Firefox 151 and Thunderbird 151.
Defensive priority
High
Recommended defensive actions
- Upgrade Mozilla Firefox to 151 or later.
- Upgrade Mozilla Thunderbird to 151 or later.
- Verify fleet inventories for Firefox and Thunderbird versions earlier than 151.0.0.
- Prioritize remediation on systems that use WebRTC features or are exposed to higher-risk browsing and messaging workflows.
- Use the linked Mozilla advisories and NVD record to validate affected versions and track any follow-up updates.
Evidence notes
This debrief is based only on the supplied NVD source item and official links. The source metadata lists Mozilla as the vendor, a privilege-escalation issue in the WebRTC: Audio/Video component, NVD severity of 8.8 High, CVSS vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, and CWE-269. The referenced Mozilla Bugzilla entry and two Mozilla security advisories support the vendor-side disclosure trail. The supplied record states the fix landed in Firefox 151 and Thunderbird 151, with vulnerable CPE ranges ending before 151.0.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8972 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8972
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8972 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8972
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-46/
[email protected] - Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.mozilla.org/security/advisories/mfsa2026-50/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.