PT-2026-34019 · Freescout · Freescout
Published
2026-04-21
·
Updated
2026-04-27
·
CVE-2026-40569
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.213
Description
An issue exists in the mailbox connection settings endpoints where the functions
connectionIncomingSave() and connectionOutgoingSave() pass all request data directly to the mailbox fill method without field allowlisting. This allows an authenticated administrator to overwrite security-critical fields in the Mailbox model, such as auto bcc, out server, out password, signature, auto reply enabled, and auto reply message, by appending hidden parameters to a legitimate request. This can lead to silent email exfiltration by BCCing outgoing emails to an external address, redirecting SMTP traffic through an attacker-controlled server, or injecting malicious content into email signatures and auto-replies.Recommendations
Update to version 1.8.213.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freescout