CVE-2026-6765
MediumPublished
Information disclosure in the Form Autofill component
- Published
- Apr 21, 2026
- Updated
- May 27, 2026
- Assigning CNA
- mozilla
- Evidence observed
- Aug 17, 2026
Primary CVSS
5.3/ 10Medium
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N0.2%
Low · next 30 days
- Percentile
- 12.2%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Sources
1- SkeletonKeyPoC
CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.