PT-2026-34026 · Freescout · Freescout

CVE-2026-40591

·

Published

2026-04-21

·

Updated

2026-04-27

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.214
Description The phone-conversation creation flow allows the use of attacker-controlled customer id, name, to email, and phone values. The system resolves the target customer in the backend without enforcing mailbox-scoped customer visibility. This enables a low-privileged agent with permissions to create a phone conversation in one mailbox to bind that conversation to a hidden customer from another mailbox and add a new alias email to the hidden customer record via the to email parameter.
Recommendations Update to version 1.8.214.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40591
GHSA-9FF4-MMHV-X6JP

Affected Products

Freescout