CVE-2026-40498: FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APPKEY, which is exposed in the response and logs. Accessing these endpoints reveals sensitive server information (Full Path Disclosure), process IDs, and allows for Resource Exhaustion (DoS) by triggering heavy background tasks repeatedly without any rate limiting. The cron hash is generated using md5(APPKEY . 'webcronhash'). Since this hash is often transmitted via GET requests, it is susceptible to exposure in server logs, browser history, and proxy logs. Furthermore, the lack of rate limiting on these endpoints allows for automated resource exhaustion (DoS) and brute-force attempts. Version 1.8.213 fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40498?
CVE-2026-40498 has been classified with a high severity due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2026-40498?
To fix CVE-2026-40498, it is recommended to upgrade FreeScout to version 1.8.213 or later.
What are the implications of CVE-2026-40498 for FreeScout users?
CVE-2026-40498 allows unauthenticated attackers to access diagnostic and system tools intended for administrators, posing significant security risks.
Which versions of FreeScout are affected by CVE-2026-40498?
CVE-2026-40498 affects all versions of FreeScout prior to 1.8.213.
Is it possible to exploit CVE-2026-40498 without authentication?
Yes, CVE-2026-40498 can be exploited by unauthenticated attackers.