


Perceptive Security
SOC/SIEM Consultancy

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email addr…
Published:
20 April 2026 at 22:00:00
Alert date:
21 April 2026 at 18:10:28
Source:
nvd.nist.gov
Enterprise Applications, Data Breach & Exfiltration, Email & Messaging
FreeScout help desk software contains a vulnerability prior to version 1.8.214 where low-privileged agents can exploit customer email management functionality. The vulnerability allows agents to edit visible customers and add email addresses owned by hidden customers from other mailboxes. This results in unauthorized disclosure of hidden customer names and profile URLs through server success messages. The exploit also causes email reassignment and rebinding of conversations from hidden mailboxes to visible customers, potentially exposing sensitive customer communications and data.
Technical details
Mitigation steps:
Affected products:
FreeScout
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40589
https://github.com/freescout-help-desk/freescout/commit/2e2fe37111d92ac665b9ad8806eac94a1a3e502c
https://github.com/freescout-help-desk/freescout/releases/tag/1.8.214
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mv55-3mgv-fxwr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
