Review reviewCritical
CVE-2026-50886
the affected product
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
- CVSS
- 9.1
- EPSS
- 0.31% 23.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.16