Vulnerability Description
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability was fixed in Thunderbird 136 and Thunderbird 128.8.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Thunderbird | < 128.8.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1864205Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2025-17/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-18/Vendor Advisory
FAQ
What is CVE-2025-26696?
CVE-2025-26696 is a vulnerability with a CVSS score of 7.0 (HIGH). Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown as being encrypted. This vulnerability w...
How severe is CVE-2025-26696?
CVE-2025-26696 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26696?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Thunderbird.