PT-2026-30895 · Freescout Help Desk · Freescout

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35584

CVSS v4.0

6.9

Medium

AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation id}/{thread id} does not require authentication and does not validate whether the given thread id belongs to the given conversation id. This allows any unauthenticated attacker to mark any thread as read by passing arbitrary IDs, enumerate valid thread IDs via HTTP response codes (200 vs 404), and manipulate opened at timestamps across conversations (IDOR). This vulnerability is fixed in 1.8.212.

Fix

Missing Authentication

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-35584

Affected Products

Freescout