CVE-2026-40591: FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Customer Modification
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled customerid, name, toemail, and phone values and resolves the target customer in the backend without enforcing mailbox-scoped customer visibility. As a result, a low-privileged agent who can create a phone conversation in Mailbox A can bind the new Mailbox A phone conversation to a hidden customer from Mailbox B and add a new alias email to that hidden customer record by supplying toemail. Version 1.8.214 fixes the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40591?
CVE-2026-40591 has been classified with a medium severity due to its potential for unauthorized access to sensitive customer information.
How do I fix CVE-2026-40591?
To mitigate CVE-2026-40591, upgrade FreeScout to version 1.8.214 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-40591?
CVE-2026-40591 is categorized as an improper authorization vulnerability affecting the phone conversation creation feature.
What versions of FreeScout are affected by CVE-2026-40591?
CVE-2026-40591 affects all versions of FreeScout prior to 1.8.214.
Who is impacted by the CVE-2026-40591 vulnerability?
Users of FreeScout versions before 1.8.214 may be impacted, specifically those utilizing the phone conversation creation feature.