
PEACH
Un cadre d’isolation des locataires
CVE-2026-84641 is an information disclosure vulnerability in Mozilla Thunderbird caused by a use-after-free condition triggered by a malicious IMAP server response. When Thunderbird connects to a rogue IMAP server, the server can send a crafted ID response that causes heap-memory contents to be disclosed and potentially persisted to the user's prefs.js file. The vulnerability was disclosed on September 1, 2026, and affects Thunderbird versions prior to 155, 140.15 (ESR), and 153.2 (ESR). It is rated low impact by Mozilla and estimated as Medium severity by Feedly; an official CVSS score had not been published at time of writing (Mozilla Advisory MFSA2026-86, Mozilla Advisory MFSA2026-87, Mozilla Advisory MFSA2026-88).
The root cause is classified as CWE-825 (Expired Pointer Dereference), manifesting as a use-after-free when Thunderbird processes a crafted IMAP ID command response from a server it is connected to. The freed heap memory is subsequently read and its contents can be written to the user's prefs.js preferences file, enabling persistent exfiltration of sensitive heap data. Exploitation requires the victim's Thunderbird client to connect to an attacker-controlled or compromised IMAP server — either by tricking the user into configuring a malicious account or by performing a man-in-the-middle attack on an existing IMAP connection. The bug was reported by researcher ABDULAZIZ ALASAIQAH and tracked internally as Mozilla Bug 2057805 (Mozilla Advisory MFSA2026-86, Red Hat Bugzilla).
Successful exploitation results in disclosure of heap memory contents from the Thunderbird process, which may include sensitive data such as credentials, session tokens, or other in-memory secrets. These heap contents can be persisted to the prefs.js file on disk, potentially allowing an attacker with subsequent file-system access to retrieve the disclosed data. The vulnerability does not directly enable remote code execution or privilege escalation, and its impact is limited to confidentiality (Mozilla Advisory MFSA2026-86, Mozilla Advisory MFSA2026-88).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-84641 as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to control or impersonate an IMAP server that the victim connects to, raising the bar for opportunistic attacks (Feedly, Red Hat Bugzilla).
ID command response.ID response that triggers a use-after-free condition in Thunderbird's IMAP handling code.prefs.js file on disk.prefs.js file (e.g., via a subsequent file-access vector, social engineering, or if the server interaction itself allows data to be sent back) to extract the disclosed heap contents (Mozilla Advisory MFSA2026-86, Red Hat Bugzilla).ID command/response traffic captured in network logs.prefs.js file (e.g., binary-looking or garbled strings in preference values); recent modification timestamps on prefs.js coinciding with IMAP session activity.prefs.js at unusual times.Mozilla has released patched versions that address CVE-2026-84641: Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2. Users should update to one of these versions immediately. No configuration-based workaround has been published; the recommended action is to upgrade. As an additional precaution, users should avoid connecting Thunderbird to untrusted or unknown IMAP servers and ensure IMAP connections use TLS to reduce man-in-the-middle risk (Mozilla Advisory MFSA2026-86, Mozilla Advisory MFSA2026-87, Mozilla Advisory MFSA2026-88).
Mozilla rated this vulnerability as low impact in all three security advisories published on September 1, 2026, noting that scripting-based flaws generally cannot be exploited through email in Thunderbird. Red Hat opened a high-priority security tracking bug (Bug 2527115) for downstream package maintainers. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Mozilla Advisory MFSA2026-86, Red Hat Bugzilla).
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bookworm
thunderbird: 1:140.15.0esr-1~deb12u1
sid
thunderbird: 1:153.2.0esr-1
trixie
thunderbird: 1:140.15.0esr-1~deb13u1
devel
thunderbird
jammy
thunderbird
noble
thunderbird
resolute
thunderbird
RHEL 8
thunderbird.src
RHEL 9
thunderbird.src
RHEL 10
thunderbird.src
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."