
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-84642 is an authorization bypass vulnerability in Mozilla Thunderbird caused by unescaped regular expression handling of the mail.allowed_attachment_hostnames advanced configuration setting. When hostnames configured in this allowlist contain regex metacharacters, they are used directly in a regular expression without proper escaping, allowing certain unintended hostnames to match and serve remote attachments. The vulnerability affects Thunderbird versions prior to 155.0 (in the 154.x branch) and prior to 153.2.0 (in the ESR branch), and was disclosed on September 1, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Mozilla MFSA2026-86, Mozilla MFSA2026-88).
The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity) and maps to CAPEC-492 (Regular Expression Exponential Blowup), reflecting improper handling of user-supplied input in regex construction. Thunderbird's attachment hostname allowlist feature reads values from mail.allowed_attachment_hostnames and incorporates them directly into a regular expression pattern without escaping special regex metacharacters. For hostnames that happen to contain characters with regex significance (e.g., ., *, +), the resulting pattern can inadvertently match additional, unintended hostnames, bypassing the intended access restriction. This is a network-accessible flaw requiring no authentication or user interaction, as the matching occurs automatically when remote attachments are processed (Mozilla MFSA2026-86, Mozilla MFSA2026-88).
Successful exploitation allows an unauthenticated remote attacker to serve remote attachments from hostnames that should be blocked by the configured allowlist, effectively bypassing Thunderbird's attachment hostname restriction. The primary impact is a high confidentiality risk — users may unknowingly load or interact with remote content from unauthorized sources — while integrity and availability are not directly affected. The scope is limited to Thunderbird clients with a non-empty mail.allowed_attachment_hostnames configuration containing hostnames with regex-special characters (Mozilla MFSA2026-86, Mozilla MFSA2026-88).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is automatable (per NVD SSVC assessment) but has only partial technical impact. The EPSS score is approximately 0.148%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
Mozilla has released patches addressing this vulnerability in Thunderbird 155 and Thunderbird ESR 153.2, both announced on September 1, 2026. Users should update to one of these versions immediately via the built-in updater or their platform's package manager. As an additional precaution, administrators should review the mail.allowed_attachment_hostnames setting in Thunderbird's advanced configuration (about:config) to ensure it contains only intended, properly formatted hostnames, and consider clearing or restricting this setting if remote attachment functionality is not required (Mozilla MFSA2026-86, Mozilla MFSA2026-88).
Mozilla rated the impact of CVE-2026-84642 as "low" within the broader Thunderbird 155 and 153.2 security advisories, which collectively addressed numerous higher-severity issues. The vulnerability was reported by researchers ChinhNguyen and Lowk3yz. No significant independent researcher commentary, media coverage, or notable community discussion specific to this CVE has been identified beyond standard vulnerability aggregator coverage (Mozilla MFSA2026-86, Mozilla MFSA2026-88).
Disponibilidade de correção em distribuições Linux principais e suas versões.
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."