CVE-2026-40498: FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron

Published Apr 21, 2026
·
Updated

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APPKEY, which is exposed in the response and logs. Accessing these endpoints reveals sensitive server information (Full Path Disclosure), process IDs, and allows for Resource Exhaustion (DoS) by triggering heavy background tasks repeatedly without any rate limiting. The cron hash is generated using md5(APPKEY . 'webcronhash'). Since this hash is often transmitted via GET requests, it is susceptible to exposure in server logs, browser history, and proxy logs. Furthermore, the lack of rate limiting on these endpoints allows for automated resource exhaustion (DoS) and brute-force attempts. Version 1.8.213 fixes the issue.

Affected Software

2 affected components
Freescout freescout<1.8.213
Freescout freescout<1.8.213

Event History

Apr 21, 2026
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-40498?

CVE-2026-40498 has been classified with a high severity due to its potential for unauthorized access to sensitive information.

2

How do I fix CVE-2026-40498?

To fix CVE-2026-40498, it is recommended to upgrade FreeScout to version 1.8.213 or later.

3

What are the implications of CVE-2026-40498 for FreeScout users?

CVE-2026-40498 allows unauthenticated attackers to access diagnostic and system tools intended for administrators, posing significant security risks.

4

Which versions of FreeScout are affected by CVE-2026-40498?

CVE-2026-40498 affects all versions of FreeScout prior to 1.8.213.

5

Is it possible to exploit CVE-2026-40498 without authentication?

Yes, CVE-2026-40498 can be exploited by unauthenticated attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203