CVE-2026-107393: FreeScout: Stored HTML Injection in Administrator Alert Emails via Spoofed CF-Connecting-IP Header

Published Oct 8, 2026
·
Updated

FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APPCLOUDFLAREISUSED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.

Affected Software

1 affected component
Freescout freescout<1.8.235

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeScout to a version that resolves this vulnerability.

    Fixed in 1.8.235

Event History

Oct 8, 2026
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

FreeScout deployments prior to 1.8.235 are affected when APP_CLOUDFLARE_IS_USED is enabled. The issue involves failed-login activity logging and administrator alert emails generated by LogsMonitor.

2

What does an attacker need to do to exploit this?

An attacker needs network access to submit failed login attempts and must be able to send a spoofed CF-Connecting-IP header. Exploitation also requires an administrator to open the resulting alert email.

3

Is authentication required for exploitation?

No. The vector is a failed login attempt, and the supplied CVSS vector lists privileges required as none.

4

How can I remediate the issue?

Upgrade FreeScout to version 1.8.235, which fixes the vulnerability. If upgrading cannot happen immediately, disabling APP_CLOUDFLARE_IS_USED removes the configuration condition described as enabling the vulnerable header handling.

5

How can I assess whether exploitation may have occurred?

Review failed-login activity records and related administrator alert emails for unexpected HTML or suspicious values in the logged client IP field. The spoofed CF-Connecting-IP value is stored in the activity log and inserted into alert emails.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203