SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57501

NONE · CVSS 0 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The Zen browser, based on Firefox, has a vulnerability that allows malicious web pages to exploit context-menu actions to load file URLs with elevated System privileges, bypassing standard security checks. This could enable attackers to access sensitive files or execute unauthorized actions on the user's system. Users of Zen prior to version 1.21.5b should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57501
Severity
NONE
CVSS
0
EPSS
0.29%
Firefox

Original NVD Description

Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click. This issue is fixed in version 1.21.5b.