
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-84641 is an information disclosure vulnerability in Mozilla Thunderbird titled "Information disclosure due to malicious IMAP server response." A malicious IMAP server can trigger a use-after-free and heap-memory disclosure by sending a crafted IMAP ID response; the exposed heap contents can ultimately be persisted to the user's prefs.js file. The vulnerability affects Thunderbird versions prior to 155, prior to 140.15 (ESR), and prior to 153.2 (ESR). It was discovered by researcher ABDULAZIZ ALASAIQAH, disclosed and patched on September 1, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Mozilla MFSA 2026-86, Mozilla MFSA 2026-87, Mozilla MFSA 2026-88).
The root cause is a use-after-free (CWE-416) combined with an expired pointer dereference (CWE-825) in Thunderbird's IMAP client code when processing the server's ID command response. When a maliciously crafted IMAP ID response is received, Thunderbird accesses already-freed heap memory, leaking its contents. The leaked heap data can then be written to the user's prefs.js preferences file, potentially exposing sensitive in-memory data to an attacker who controls or can observe that file. Exploitation requires no user interaction and no privileges — only that the victim's Thunderbird client connects to a malicious or compromised IMAP server (Mozilla MFSA 2026-86, Red Hat Bugzilla).
Successful exploitation results in a high-confidentiality impact: sensitive heap memory contents from the Thunderbird process are disclosed and can be persisted to prefs.js on disk, potentially exposing credentials, session tokens, or other sensitive data stored in memory. There is no direct integrity or availability impact. The vulnerability is rated "low" impact by Mozilla in the context of Thunderbird's email reading mode (where scripting is disabled), but poses a meaningful risk when users connect to untrusted or attacker-controlled IMAP servers (Mozilla MFSA 2026-86, Mozilla MFSA 2026-87).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-84641. The EPSS score is approximately 0.0015 (0.15%), indicating a low probability of exploitation in the near term. The NVD assessment notes the vulnerability is automatable (no user interaction required) but exploitation has not been observed. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Mozilla MFSA 2026-86, Red Hat Bugzilla).
prefs.js file on disk. The attacker then reads prefs.js (if they have local access) or exfiltrates it through another vector to extract sensitive data such as credentials or session tokens (Mozilla MFSA 2026-86, Red Hat Bugzilla).prefs.js file — particularly binary-looking or garbled data that does not correspond to valid preference values; sudden increase in prefs.js file size.* ID (...) command).Mozilla has released patched versions addressing CVE-2026-84641: Thunderbird 155, Thunderbird ESR 140.15, and Thunderbird ESR 153.2. Users should update to one of these versions immediately. As a workaround, users can avoid connecting Thunderbird to untrusted or unknown IMAP servers until the patch is applied. No configuration-based workaround within Thunderbird has been documented by Mozilla (Mozilla MFSA 2026-86, Mozilla MFSA 2026-87, Mozilla MFSA 2026-88).
Mozilla rated this vulnerability as "low" impact in the context of Thunderbird's email reading mode, noting that scripting is disabled when reading mail. Red Hat tracked the issue as low severity in their Bugzilla system. The vulnerability was part of a broader September 1, 2026 Thunderbird security release that addressed 38 vulnerabilities across Firefox and Thunderbird, which received coverage from Linux security news outlets (Mozilla MFSA 2026-86, Red Hat Bugzilla).
主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。
bookworm
thunderbird: 1:140.15.0esr-1~deb12u1
sid
thunderbird: 1:153.2.0esr-1
trixie
thunderbird: 1:140.15.0esr-1~deb13u1
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"