PT-2026-34039 · Freescout Help Desk · Freescout
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-41192
CVSS v3.1
7.1
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.215
Description
The reply and draft flows trust encrypted attachment IDs supplied by the client. Any IDs included in the
attachments all[] variable but omitted from retained lists are decrypted and passed to the deleteByIds() function of the Attachment class. Since load attachments returns encrypted IDs for attachments within a visible conversation, a mailbox peer can replay these IDs through the 'save draft' endpoint to delete the original attachment row and file.Recommendations
Update to version 1.8.215.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout