CVE Vulnerabilities

CVE-2026-0887

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Published: Jan 13, 2026 | Modified: Jan 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.

Weakness

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*140.7.0 (excluding)
FirefoxMozilla*147.0 (excluding)
ThunderbirdMozilla*140.7.0 (excluding)
ThunderbirdMozilla*147.0 (excluding)
Red Hat Enterprise Linux 10RedHatfirefox-0:140.7.0-1.el10_1*
Red Hat Enterprise Linux 10RedHatthunderbird-0:140.7.0-1.el10_1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatfirefox-0:140.7.0-1.el10_0*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatthunderbird-0:140.7.0-1.el10_0*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatfirefox-0:140.7.0-1.el7_9*
Red Hat Enterprise Linux 8RedHatfirefox-0:140.7.0-1.el8_10*
Red Hat Enterprise Linux 8RedHatthunderbird-0:140.7.0-1.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatthunderbird-0:140.7.0-1.el8_2*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatfirefox-0:140.7.0-1.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatthunderbird-0:140.7.0-1.el8_4*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatfirefox-0:140.7.0-1.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatthunderbird-0:140.7.0-1.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatfirefox-0:140.7.0-1.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatthunderbird-0:140.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatfirefox-0:140.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatthunderbird-0:140.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatfirefox-0:140.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatthunderbird-0:140.7.0-1.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatfirefox-0:140.7.0-1.el8_6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatthunderbird-0:140.7.0-1.el8_8*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatfirefox-0:140.7.0-1.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatthunderbird-0:140.7.0-1.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatfirefox-0:140.7.0-1.el8_8*
Red Hat Enterprise Linux 9RedHatfirefox-0:140.7.0-1.el9_7*
Red Hat Enterprise Linux 9RedHatthunderbird-0:140.7.0-1.el9_7*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatthunderbird-0:140.7.0-1.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatfirefox-0:140.7.0-1.el9_0*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatthunderbird-0:140.7.0-1.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatfirefox-0:140.7.0-1.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatthunderbird-0:140.7.0-1.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatfirefox-0:140.7.0-1.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatthunderbird-0:140.7.0-2.el9_6*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatfirefox-0:140.7.0-1.el9_6*
Mozjs102Ubuntuesm-apps/noble*
Mozjs102Ubuntujammy*
Mozjs102Ubuntunoble*
Mozjs115Ubuntunoble*
Mozjs115Ubuntuplucky*
Mozjs52Ubuntuesm-apps/focal*
Mozjs52Ubuntuesm-infra/bionic*
Mozjs68Ubuntuesm-infra/focal*
Mozjs78Ubuntuesm-apps/jammy*
Mozjs78Ubuntujammy*
Mozjs91Ubuntujammy*
ThunderbirdUbuntujammy*

Extended Description

Network-based products, such as web applications, often run on top of an operating system or similar environment. When the product communicates with outside parties, details about the underlying system are expected to remain hidden, such as path names for data files, other OS users, installed packages, the application environment, etc. This system information may be provided by the product itself, or buried within diagnostic or debugging messages. Debugging information helps an adversary learn about the system and form an attack plan. An information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism.

Potential Mitigations

References