CVE-2026-0890
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0890 is a spoofing vulnerability in the DOM: Copy & Paste and Drag & Drop component of Mozilla Firefox and Thunderbird. The flaw causes the clipboard "paste" button to persist after tab navigation, potentially misleading users about the context in which clipboard access is being granted. It affects Firefox before version 147, Firefox ESR before 140.7, Thunderbird before 147, and Thunderbird ESR before 140.7. Disclosed on January 13, 2026, it carries a CVSS v3.1 base score of 5.4 (Medium), as assessed by CISA-ADP (Mozilla Advisory Firefox 147, Mozilla Advisory ESR 140.7).

Technical details

The root cause is classified as CWE-290 (Authentication Bypass by Spoofing). Specifically, the clipboard "paste" button — which requests user permission for clipboard access — fails to be dismissed when the user navigates to a different tab, causing it to persist and remain associated with an inactive document. This means a user could be tricked into granting clipboard access to a page they have already navigated away from, as the UI element does not correctly reflect the current browsing context. The bug was reported internally by Edgar Chen and is tracked in Mozilla's Bugzilla as Bug 2005081 (Mozilla Bugzilla). The fix involved ensuring the clipboard paste button is dismissed upon navigation, following similar prior fixes for navigation-based spoofing with panels.

Impact

Successful exploitation could allow a malicious web page to spoof the clipboard permission UI, potentially tricking a user into granting clipboard read access to a page they have navigated away from. This primarily affects confidentiality, as an attacker could gain unauthorized access to clipboard contents (e.g., copied passwords, sensitive text), and availability is marginally impacted. Mozilla rated this vulnerability as "low" impact, and there is no evidence of integrity compromise or lateral movement potential beyond the browser session (Mozilla Advisory Firefox 147, Mozilla Bugzilla).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-0890. The vulnerability requires user interaction (the user must navigate tabs while a clipboard paste prompt is active), limiting its practical exploitability. The EPSS score is approximately 0.038%, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Mozilla Advisory Firefox 147).

Exploitation steps

  1. Set up a malicious page: Host a web page that triggers a clipboard paste permission prompt (e.g., using the Clipboard API to request read access), causing the browser to display a "Paste" button to the user.
  2. Induce tab navigation: Use social engineering or automated redirection to cause the user to navigate away from the malicious page to another tab or URL while the clipboard paste button is still visible.
  3. Exploit persistent UI: Due to the bug, the clipboard paste button remains displayed even after navigation, still associated with the original (now inactive) malicious document.
  4. Capture clipboard data: If the user clicks the persisted paste button, clipboard contents are sent to the original malicious page's document context, potentially exposing sensitive copied data to the attacker (Mozilla Bugzilla).

Mitigation and workarounds

Mozilla has released patches addressing this vulnerability in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird ESR 140.7. Users and administrators should update to these versions or later immediately. No configuration-based workaround is available; upgrading is the only remediation. Enterprise deployments using ESR should target version 140.7 or later (Mozilla Advisory Firefox 147, Mozilla Advisory ESR 140.7).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Mozilla products fixed in this release cycle, including CVE-2026-0890, flagging the overall update as addressing issues that could allow arbitrary code execution in other CVEs bundled in the same release. Coverage was largely routine, with security news outlets such as CyberSecurityNews reporting on the Firefox 147 release and its 16 vulnerability fixes collectively. No significant independent researcher commentary or social media discussion specific to CVE-2026-0890 has been identified, consistent with its low severity rating.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

thunderbird: 1:140.7.0esr-1~deb12u1

Fixed

sid

thunderbird: 1:140.7.0esr-1

Fixed

trixie

thunderbird: 1:140.7.0esr-1~deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

mozjs38

Unknown

devel

firefox

Not Affected

jammy

thunderbird: 1:140.7.1+build1-0ubuntu0.22.04.1

Fixed

noble

firefox

Not Affected

questing

firefox

Not Affected

resolute

firefox

Not Affected

RHEL / CentOS

Fixed

RHEL 8

:appstream:firefox-0:140.7.0-1.el8_10.src

Fixed

RHEL 9

:appstream:firefox-0:140.7.0-1.el9_0.src

Fixed

RHEL 10

firefox-0:140.7.0-1.el10_0.src

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management