Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Mozilla Firefox
Exploit
CVE-2026-8948
VulnCheck
Refer to CVE-2026-8948 NVD advisory