CVE-2026-4705 is a critical undefined behavior vulnerability (CVSS 9.8) found in the WebRTC: Signaling component, affecting Mozilla Firefox versions prior to 149, Firefox ESR prior to 140.9, and Thunderbird versions prior to 149 and 140.9. This remotely exploitable flaw requires no user interaction (AV:N/UI:N) and could lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Despite its high severity, there is currently no evidence of active exploitation in the wild, nor are public exploit modules available on platforms like Metasploit or ExploitDB. However, the vulnerability has generated some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.