---
cve: "CVE-2026-100831"
severity: "HIGH"
cvss: 8.8
epss: "0.3%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-09-29 13:17:48"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-03T07:59:17+02:00"
---

# CVE-2026-100831

> 8.8 HIGH

## Beschreibung

Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

## CNA-Record (Kanon, cvelistV5)

- CNA: **mozilla**
- State: PUBLISHED
- Stand: 2026-09-30 17:21:15

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3654) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox ESR und Mozilla Firefox ausnutzen, um beliebigen Programmcode auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder andere, nicht näher spezifizierte Angriffe zu starten.

## Referenzen

- <https://bugzilla.mozilla.org/show_bug.cgi?id=2067172>
- <https://www.mozilla.org/security/advisories/mfsa2026-100/>
- <https://www.mozilla.org/security/advisories/mfsa2026-101/>
- <https://www.mozilla.org/security/advisories/mfsa2026-103/>
- <https://www.mozilla.org/security/advisories/mfsa2026-97/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-100831) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
