CVE-2023-4104: Mozilla VPN

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN 2.16.1 < (Linux).

Affected products

  • Mozilla VPN: before 2.16.1 (fixed in 2.16.1)

Published 2023-09-11. Last modified 2026-06-17.