CVE-2026-28289: FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution

Published Mar 3, 2026
·
Updated

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.

Affected Software

2 affected components
Freescout freescout<1.8.206
Freescout freescout<1.8.207

Event History

Mar 3, 2026
CVE Published
via MITRE·10:59 PM
Data Sourced
via MITRE·10:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 4, 2026
News Published
via BleepingComputer·09:51 PM
News Published
via BleepingComputer·09:52 PM
Mar 6, 58156
Event
via FIRST·04:53 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-28289?

CVE-2026-28289 is classified as a high severity vulnerability due to its potential for remote code execution.

2

How can I mitigate CVE-2026-28289?

To mitigate CVE-2026-28289, upgrade to FreeScout version 1.8.207 or later, which contains a fix for this vulnerability.

3

Who is affected by CVE-2026-28289?

All users of FreeScout version 1.8.206 and earlier who are authenticated are affected by CVE-2026-28289.

4

What type of vulnerability is CVE-2026-28289?

CVE-2026-28289 is a patch bypass vulnerability that can lead to remote code execution.

5

What should I do if I cannot immediately update for CVE-2026-28289?

If you cannot update immediately for CVE-2026-28289, consider limiting access to the affected application and monitoring for suspicious activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203