


Perceptive Security
SOC/SIEM Consultancy

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside th…
Published:
20 April 2026 at 22:00:00
Alert date:
21 April 2026 at 18:10:28
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
FreeScout is a free self-hosted help desk and shared mailbox application. Prior to version 1.8.215, the MailboxesController::updateSave() function persists chat_start_new outside the allowed-field filter. This vulnerability allows users with only the mailbox signature permission to change hidden mailbox-wide chat settings through direct POST requests, bypassing UI restrictions. The vulnerability represents a privilege escalation where restricted users can modify settings they should not have access to. Version 1.8.215 addresses this security flaw.
Technical details
Mitigation steps:
Affected products:
FreeScout
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41191
https://github.com/freescout-help-desk/freescout/commit/fb130de64e1c830d85dd6988eaa08d725a7be954
https://github.com/freescout-help-desk/freescout/releases/tag/1.8.215
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wpv9-c2gv-2j82
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
