CVE-2026-27637: FreeScout's Predictable Authentication Token Enables Account Takeover
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's TokenAuth middleware uses a predictable authentication token computed as MD5(userid + createdat + APPKEY). This token is static (never expires/rotates), and if an attacker obtains the APPKEY — a well-documented and common exposure vector in Laravel applications — they can compute a valid token for any user, including the administrator, achieving full account takeover without any password. This vulnerability can be exploited on its own or in combination with CVE-2026-27636. Version 1.8.206 fixes both vulnerabilities.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27637?
CVE-2026-27637 has a high severity rating due to its potential for account takeover.
How do I fix CVE-2026-27637?
To fix CVE-2026-27637, upgrade to FreeScout version 1.8.206 or later.
What type of vulnerability is CVE-2026-27637?
CVE-2026-27637 is a predictable authentication token vulnerability that enables account takeover.
Which versions of FreeScout are affected by CVE-2026-27637?
FreeScout versions prior to 1.8.206 are affected by CVE-2026-27637.
What impact does CVE-2026-27637 have on user accounts?
CVE-2026-27637 can allow an attacker to take over user accounts due to the predictable authentication mechanism.