CVE-2026-40570: FreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Full Customer PII
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the loadcustomerinfo action in POST /conversation/ajax returns complete customer profile data to any authenticated user without verifying mailbox access. An attacker only needs a valid email address to retrieve all customer PII. Version 1.8.213 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40570?
CVE-2026-40570 is considered a critical vulnerability due to its potential to expose sensitive customer PII to unauthorized users.
How do I fix CVE-2026-40570?
To resolve CVE-2026-40570, upgrade to FreeScout version 1.8.213 or later, which includes the necessary security patches.
What is affected by CVE-2026-40570?
CVE-2026-40570 affects FreeScout versions prior to 1.8.213, impacting the security of customer data handling.
What does CVE-2026-40570 exploit?
CVE-2026-40570 exploits a missing authorization check in the `load_customer_info` action, allowing access to full customer profiles.
Who is impacted by CVE-2026-40570?
Any authenticated user on systems prior to FreeScout version 1.8.213 may be impacted by CVE-2026-40570, risking exposure of personal information.