CVE-2023-4104: Mozilla VPN
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. *This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected.* This vulnerability affects Mozilla VPN 2.16.1 < (Linux).
Affected products
- Mozilla VPN: before 2.16.1 (fixed in 2.16.1)
Published 2023-09-11. Last modified 2026-06-17.