PT-2026-26373 · Freescout+1 · Freescout+1

Offensiveee

·

Published

2026-03-19

·

Updated

2026-03-24

·

CVE-2026-32752

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions 1.8.208 and below
Description FreeScout is a help desk and shared inbox application built with the Laravel PHP framework. A broken access control issue exists in the ThreadPolicy::edit() method. This allows any authenticated user, regardless of their role or mailbox access, to read and modify all customer-created thread messages across all mailboxes. This flaw enables silent modification of customer messages and bypasses the entire mailbox permission model, potentially leading to GDPR compliance violations. The ThreadPolicy::edit() function is vulnerable to unauthorized access. The vulnerable parameter is not specified.
Recommendations Upgrade to version 1.8.209 or later to resolve this issue.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-32752
GHSA-WXG5-G9VV-V8G9

Affected Products

Freescout
Laravel