PT-2026-44996 · Freescout · Freescout

Geo-Chen

·

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-48811

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.221
Description Non-admin users can permanently delete internal notes (private threads) from any conversation. This occurs because the ThreadPolicy::delete authorization policy fails to verify mailbox membership, allowing former team members to maintain destructive write access to notes they created even after their access to the mailbox has been revoked.
Recommendations Update to version 1.8.221.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48811

Affected Products

Freescout