PT-2026-30898 · Freescout+1 · Freescout+1

·

CVE-2026-39384

·

Published

2026-04-07

·

Updated

2026-04-07

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.212
Description FreeScout, a help desk and shared inbox built with PHP's Laravel framework, does not properly consider the limit user customer visibility parameter when merging customers in versions prior to 1.8.212.
Recommendations Update to version 1.8.212 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39384
GHSA-J6V9-22VQ-53VH

Affected Products

Freescout
Laravel