CVE-2026-74985
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154,
CVSS
9.8
Critical
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Aug 18, 2026 · Last modified: Aug 25, 2026 · CWE-269
0.1%EPSS · 30 days0.3%
2026-08-192026-09-09
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2059825
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-74/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-77/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-78/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-80/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-879588.1 HIG—
———IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.13hCVE-2026-757778.8 HIG—
———IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.13hCVE-2026-93276.3 MED—
———IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.14hCVE-2026-888918.3 HIG—
———OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.20hCVE-2026-888638.1 HIG—
———capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles permission for org_super_admin invitations, so an authenticated user holding only the org.invite_user permission (e.g., an org_member) can invite an external user as org_admin or org_billing_admin. When the invited account accepts the invitation via POST /private/accept_invitation, ensureOrgMembership creates the role binding using the Supabase service-role key, which bypasses the prevent_role_binding_priority_escalation and check_org_user_privileges database triggers. This allows privilege escalation resulting in full administrative control over the organization's apps, channels, members, and billing. The issue is addressed by pull request #3096, which compares the inviter's rank before permitting elevated invitations.20hCVE-2026-840427.8 HIG—
———A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.2917h