CVE-2026-40592: FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route GET /conversation/undo-reply/{threadid} checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In a shared mailbox, one agent can therefore recall another agent's just-sent reply during the 15-second undo window. Version 1.8.214 fixes the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40592?
CVE-2026-40592 has been recognized as a significant vulnerability due to its potential impact on user privacy and data integrity.
How do I fix CVE-2026-40592?
To remediate CVE-2026-40592, upgrade FreeScout to version 1.8.214 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-40592?
CVE-2026-40592 is classified as a cross-user information disclosure vulnerability affecting the undo reply functionality.
Who is affected by CVE-2026-40592?
Any FreeScout user on versions prior to 1.8.214 is susceptible to CVE-2026-40592.
What does CVE-2026-40592 allow an attacker to do?
CVE-2026-40592 permits attackers to recall the outbound replies of other agents within a shared mailbox.