CVE-2025-26696

HIGH

Mozilla Thunderbird < 128.8.0 - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.

Scores

CVSS v3 7.0
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (3)
mozilla/thunderbird < 128.8.0
Mozilla/Thunderbird 128.8 - 128.*
Mozilla/Thunderbird 136
Published Mar 10, 2025
Tracked Since Feb 18, 2026