PT-2026-44993 · Freescout · Freescout
Fr0Z863Xf
·
Published
2026-05-29
·
Updated
2026-05-29
·
CVE-2026-47123
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.220
Description
The email processing pipeline in the
FetchEmails command contains two code paths for identifying agent replies using In-Reply-To and References headers. The notification reply path (notify-thread id-user id-...) extracts the thread id and user id directly from the Message-ID without HMAC (Hash-based Message Authentication Code) verification. This allows an external attacker to spoof the From address of a helpdesk agent and inject messages that are processed as legitimate agent replies, which are then automatically forwarded to customers via the legitimate SMTP server.Recommendations
Update to version 1.8.220.
Exploit
Fix
Authentication Bypass by Spoofing
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freescout