What is CVE-2026-74950?
This is a privilege escalation vulnerability found in the Downloads API component of Mozilla products like Firefox, Firefox ESR, and Thunderbird. Users must immediately update to the fixed versions, such as Firefox 154 and Thunderbird 154.
Azərbaycanca: Bu zəiflik Firefox, Firefox ESR, Thunderbird kimi brauzer və e-poçt müştərisi məhsullarının Downloads API komponentində aşkarlanmış imtiyaz yüksəltmə (privilege escalation) boşluğudur. İstifadəçilər təcili olaraq təqdim olunan yeni versiyalara (məsələn, Firefox 154, Thunderbird 154) yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-269
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.