Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the `last_reply_from` field is set to the attacker's identity. Version 1.8.223 contains a fix.
Published: 2026-07-20
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. An unauthenticated attacker can inject a message into any existing support conversation by sending a single email to the help desk's public address with a crafted In‑Reply‑To header. No credentials, tokens or prior access are required. The injected message appears as a legitimate customer reply in the agent UI, automatically reopens the conversation, and updates the last_reply_from field to the attacker’s identity. This vulnerability enables attackers to modify agent visibility and conversation history without authentication, constituting an authentication bypass (CWE‑287).

Affected Systems

The vulnerability affects all installations of FreeScout prior to version 1.8.223. Systems running the freescout product from the freescout‑help‑desk vendor are susceptible until a patch is applied.

Risk and Exploitability

The issue has a CVSS score of 8.6, indicating high severity. The EPSS score is 0.00215 (<1%), and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector relies only on sending a crafted email to the public address, no authentication or additional privileges are required. An attacker can add deceptive or malicious content to any conversation, potentially misleading agents or manipulating ticket status.

Generated by OpenCVE AI on July 30, 2026 at 18:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to FreeScout version 1.8.223 or newer to apply the vendor‑supplied fix.
  • If an upgrade is not immediately feasible, restrict or disable processing of external In‑Reply‑To headers from untrusted sources.
  • Continuously monitor mail logs for unexpected conversation reopenings or changes to last_reply_from and investigate any anomalies.

Generated by OpenCVE AI on July 30, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Freescout Helpdesk
Freescout Helpdesk freescout
Vendors & Products Freescout Helpdesk
Freescout Helpdesk freescout

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the `last_reply_from` field is set to the attacker's identity. Version 1.8.223 contains a fix.
Title FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Freescout Helpdesk Freescout
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-20T20:15:26.874Z

Reserved: 2026-06-09T19:11:53.485Z

Link: CVE-2026-53591

cve-icon Vulnrichment

Updated: 2026-07-20T20:15:22.271Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:45:06Z

Weaknesses