CVE-2026-50886
Received
Received - Intake
Incorrect Access Control in Firefly III Webhook Management
Publication date: 2026-06-15
Last updated on: 2026-06-15
Assigner: MITRE
Description
Description
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| firefly_iii | firefly_iii | 6.5.9 |
| project_firefly | firefly | 6.5.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |