CVE-2026-40566: FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints

Published Apr 21, 2026
·
Updated

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's MailboxesController. Three AJAX actions fetchtest (line 731), sendtest (line 682), and imapfolders (line 773) in app/Http/Controllers/MailboxesController.php pass admin-configured inserver/inport and outserver/outport values directly to fsockopen() via Helper::checkPort() and to IMAP/SMTP client connections with zero SSRF protection. There is no IP validation, no hostname restriction, no blocklist of internal ranges, and no call to the project's own sanitizeRemoteUrl() or checkUrlIpAndHost() functions. The validation block in connectionIncomingSave() is entirely commented out. An authenticated admin can configure a mailbox's IMAP or SMTP server to point at any internal host and port, then trigger a connection test. The server opens raw TCP connections (via fsockopen()) and protocol-level connections (via IMAP client or SMTP transport) to the attacker-specified target. The response differentiates open from closed ports, enabling internal network port scanning. When the IMAP client connects to a non-IMAP service, the target's service banner or error response is captured in the IMAP debug log and returned in the AJAX response's log field, making this a semi-blind SSRF that enables service fingerprinting. In cloud environments, the metadata endpoint at 169[.]254[.]169[.]254 can be probed and partial response data may be leaked through protocol error messages. This is distinct from the sanitizeRemoteUrl() redirect bypass (freescout-3) -- different code path, different root cause, different protocol layer. Version 1.8.213 patches the vulnerability.

Affected Software

1 affected component
Freescout freescout<1.8.213

Event History

Apr 21, 2026
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-40566?

CVE-2026-40566 has been classified as a high severity vulnerability due to its potential for Server-Side Request Forgery (SSRF).

2

How do I fix CVE-2026-40566?

To remediate CVE-2026-40566, upgrade FreeScout to version 1.8.213 or later as this version includes the necessary fixes.

3

What versions of FreeScout are affected by CVE-2026-40566?

FreeScout versions prior to 1.8.213 are affected by CVE-2026-40566.

4

What functionality is vulnerable in CVE-2026-40566?

The vulnerability in CVE-2026-40566 is found in the IMAP/SMTP connection test functionality of FreeScout's MailboxesController.

5

Can CVE-2026-40566 lead to unauthorized access?

Yes, CVE-2026-40566, through SSRF, could allow an attacker to make requests to internal services, potentially leading to unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203