Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212. | |
| Title | FreeScout Customer Merge Cross-Mailbox Authorization Bypass | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T16:05:16.793Z
Reserved: 2026-04-06T22:06:40.515Z
Link: CVE-2026-39384
No data.
Status : Received
Published: 2026-04-07T17:16:37.373
Modified: 2026-04-07T17:16:37.373
Link: CVE-2026-39384
No data.
OpenCVE Enrichment
No data.
Weaknesses