PT-2026-33992 · Freescout · Freescout
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-40498
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.213
Description
An unauthenticated attacker can access diagnostic and system tools intended for administrators. The '/system/cron' endpoint uses a static MD5 hash derived from the
APP KEY variable, which is exposed in responses and logs. This allows for Full Path Disclosure (revealing sensitive server paths), exposure of process IDs, and Resource Exhaustion (DoS) by repeatedly triggering heavy background tasks due to a lack of rate limiting. The hash is generated using the md5(APP KEY . 'web cron hash') function and is susceptible to exposure via GET requests in server logs, browser history, and proxy logs.Recommendations
Update to version 1.8.213.
Exploit
Fix
Improper Access Control
Information Disclosure
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freescout