


Perceptive Security
SOC/SIEM Consultancy

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility …
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 18:06:01
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
FreeScout, a free help desk and shared inbox application built with PHP's Laravel framework, contains a vulnerability prior to version 1.8.212. The application fails to properly enforce the limit_user_customer_visibility parameter when merging customers, potentially allowing unauthorized access to customer information. This access control bypass could lead to information disclosure where users can view customer data they should not have access to. The vulnerability has been addressed in FreeScout version 1.8.212 with proper enforcement of user visibility limits during customer merge operations.
Technical details
Mitigation steps:
Affected products:
FreeScout
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39384
https://github.com/freescout-help-desk/freescout/commit/b395a1179117af5e2df704c6bad71feeb301b4ce
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-j6v9-22vq-53vh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
