CVE-2026-6765 is an information disclosure vulnerability in the Form Autofill component affecting Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. The vulnerability allows unauthorized access to sensitive information through the autofill functionality in these applications. The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network-based attack vector requiring no user interaction or special privileges. The attack has low complexity and results in confidentiality impact with no integrity or availability concerns. The EPSS probability score of 0.00033 indicates this vulnerability is among the lower-probability CVEs for exploitation. There is no evidence of active exploitation in the wild, no public exploit code availability, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The moderate FAUCET risk score of 41.0 and inactive status on security hot lists suggest limited community attention and exploitation risk. Organizations should prioritize patching based on their Firefox and Thunderbird deployment scope.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.