Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the backend without enforcing mailbox-scoped customer visibility. As a result, a low-privileged agent who can create a phone conversation in Mailbox A can bind the new Mailbox A phone conversation to a hidden customer from Mailbox B and add a new alias email to that hidden customer record by supplying `to_email`. Version 1.8.214 fixes the vulnerability.
Published: 2026-04-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Customer Data Modification
Action: Apply Patch
AI Analysis

Impact

FreeScout, a self‑hosted help‑desk platform, allows a low‑privileged agent to create a phone conversation with attacker‑controlled values for customer_id, name, to_email and phone. Because the backend does not enforce mailbox‑scoped customer visibility, the agent can associate the new conversation with a hidden customer that belongs to another mailbox and add an alias email to that hidden customer record. The flaw permits unauthorized modification of customer data across mailbox boundaries, compromising data integrity and potentially exposing sensitive customer information. The weakness is identified as CWE‑639.

Affected Systems

The affected product is FreeScout Help Desk (freescout‑help‑desk). All deployments running any version before 1.8.214 are vulnerable. Version 1.8.214 and later contain a fix that validates customer visibility before creating the conversation.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity vulnerability. Exploitation requires an authenticated user with low privileges within the application, so the attack vector is an authenticated, in‑application user, not remote code execution. Because the Exploit Prediction Scoring System data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, the current likelihood of active exploitation in the wild appears to be moderate. However, the potential for cross‑mailbox data tampering warrants prompt remediation.

Generated by OpenCVE AI on April 21, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FreeScout to version 1.8.214 or later.
  • Implement or verify that the phone‑conversation creation logic validates that the referenced customer belongs to the current mailbox before creating the record.
  • Enable logging or auditing for phone‑conversation creation requests that reference hidden or cross‑mailbox customers to detect potential abuse.

Generated by OpenCVE AI on April 21, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Freescout Helpdesk
Freescout Helpdesk freescout
Vendors & Products Freescout Helpdesk
Freescout Helpdesk freescout
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Description FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the backend without enforcing mailbox-scoped customer visibility. As a result, a low-privileged agent who can create a phone conversation in Mailbox A can bind the new Mailbox A phone conversation to a hidden customer from Mailbox B and add a new alias email to that hidden customer record by supplying `to_email`. Version 1.8.214 fixes the vulnerability.
Title FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Customer Modification
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Freescout Helpdesk Freescout
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-21T17:46:38.202Z

Reserved: 2026-04-14T14:07:59.641Z

Link: CVE-2026-40591

cve-icon Vulnrichment

Updated: 2026-04-21T17:46:26.047Z

cve-icon NVD

Status : Received

Published: 2026-04-21T17:16:56.940

Modified: 2026-04-21T18:16:51.447

Link: CVE-2026-40591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T22:45:16Z

Weaknesses