CVE-2026-8958
Published: 19 May 2026
Summary
CVE-2026-8958 is a high-severity Exposure of Resource to Wrong Sphere (CWE-668) vulnerability in Mozilla Firefox. Its CVSS base score is 8.6 (High).
Operationally, ranked at the 12.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Controls whether organization resources are exposed to external system spheres by permitting or prohibiting their use.
The control ensures information is not released into a security sphere where the recipient lacks matching access authorizations.
The control ensures information resources are not exposed to the incorrect (public) sphere through review and authorization.
Protects against data mining that would expose resources to unauthorized spheres by enforcing detection and controls.
Implements a reliable, tamperproof protection mechanism whose completeness can be assured.
Restricts information flows to ensure resources are not exposed to incorrect or unauthorized spheres.
Procedures for training on protection mechanisms reduce the chance of protection mechanism failures being present or exploitable.
Documented procedures to implement assessment, authorization, and monitoring controls prevent these protection mechanisms from failing due to undefined processes.
NVD Description
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)