PT-2026-34019 · Freescout · Freescout

Published

2026-04-21

·

Updated

2026-04-27

·

CVE-2026-40569

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.213
Description An issue exists in the mailbox connection settings endpoints where the functions connectionIncomingSave() and connectionOutgoingSave() pass all request data directly to the mailbox fill method without field allowlisting. This allows an authenticated administrator to overwrite security-critical fields in the Mailbox model, such as auto bcc, out server, out password, signature, auto reply enabled, and auto reply message, by appending hidden parameters to a legitimate request. This can lead to silent email exfiltration by BCCing outgoing emails to an external address, redirecting SMTP traffic through an attacker-controlled server, or injecting malicious content into email signatures and auto-replies.
Recommendations Update to version 1.8.213.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40569

Affected Products

Freescout