Critical severity9.1NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026
CVE-2026-50886
CVE-2026-50886
Description
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
grumpydictator/firefly-iiiPackagist | <= 6.5.9 | — |
Affected products
3<= 6.5.9+ 1 more
- (no CPE)range: <= 6.5.9
- (no CPE)range: =6.5.9
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.