PT-2026-44993 · Freescout · Freescout

Fr0Z863Xf

·

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-47123

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.220
Description The email processing pipeline in the FetchEmails command contains two code paths for identifying agent replies using In-Reply-To and References headers. The notification reply path (notify-thread id-user id-...) extracts the thread id and user id directly from the Message-ID without HMAC (Hash-based Message Authentication Code) verification. This allows an external attacker to spoof the From address of a helpdesk agent and inject messages that are processed as legitimate agent replies, which are then automatically forwarded to customers via the legitimate SMTP server.
Recommendations Update to version 1.8.220.

Exploit

Fix

Authentication Bypass by Spoofing

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2026-47123

Affected Products

Freescout