CVE-2026-8948: Same-origin policy bypass in the DOM: Networking component
Published May 19, 2026
·Updated
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<151
151
Mozilla Thunderbird<151
151
Mozilla Firefox<151.0.0
Mozilla Thunderbird<151.0.0
Event History
May 19, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Jan 18, 58356
Event
via FIRST·02:34 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8948?
CVE-2026-8948 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2026-8948?
To fix CVE-2026-8948, users should upgrade to Firefox and Thunderbird version 151 or later.
3
What is CVE-2026-8948 about?
CVE-2026-8948 is a vulnerability that allows bypassing the same-origin policy in the DOM within certain Mozilla products.
4
Which versions are affected by CVE-2026-8948?
CVE-2026-8948 affects Mozilla Firefox and Thunderbird versions prior to 151.
5
Is CVE-2026-8948 exploitable remotely?
Yes, CVE-2026-8948 could potentially be exploited remotely by attackers to execute malicious actions.