CVE-2026-41189: FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through ThreadPolicy::edit(), which checks mailbox access but does not apply the assigned-only restriction from ConversationPolicy. A user who cannot view a conversation can still load and edit customer-authored threads inside it. Version 1.8.215 fixes the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41189?
CVE-2026-41189 has a medium severity rating as it allows unauthorized editing of customer-authored threads.
How do I fix CVE-2026-41189?
To fix CVE-2026-41189, upgrade FreeScout to version 1.8.215 or later.
What is the impact of CVE-2026-41189?
The impact of CVE-2026-41189 is that it enables users to edit hidden customer messages, potentially compromising confidentiality.
What versions of FreeScout are affected by CVE-2026-41189?
FreeScout versions prior to 1.8.215 are affected by CVE-2026-41189.
Who is affected by CVE-2026-41189?
Organizations using FreeScout versions below 1.8.215 are at risk because of CVE-2026-41189.