PT-2026-33992 · Freescout · Freescout

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-40498

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.213
Description An unauthenticated attacker can access diagnostic and system tools intended for administrators. The '/system/cron' endpoint uses a static MD5 hash derived from the APP KEY variable, which is exposed in responses and logs. This allows for Full Path Disclosure (revealing sensitive server paths), exposure of process IDs, and Resource Exhaustion (DoS) by repeatedly triggering heavy background tasks due to a lack of rate limiting. The hash is generated using the md5(APP KEY . 'web cron hash') function and is susceptible to exposure via GET requests in server logs, browser history, and proxy logs.
Recommendations Update to version 1.8.213.

Exploit

Fix

Improper Access Control

Information Disclosure

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40498

Affected Products

Freescout