CVE-2026-41906: FreeScout: Conversation Change-Customer Cross-Mailbox Authorization Bypass
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filtered search endpoint, but the backend conversationchangecustomer action accepts any supplied customeremail. A low-privileged agent can forge a request and bind a visible conversation to a hidden customer in another mailbox. This issue has been patched in version 1.8.214.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41906?
The severity of CVE-2026-41906 is classified as medium due to the potential for unauthorized access through a cross-mailbox authorization bypass.
How do I fix CVE-2026-41906?
To fix CVE-2026-41906, upgrade your FreeScout installation to version 1.8.214 or later.
What versions of FreeScout are affected by CVE-2026-41906?
FreeScout versions prior to 1.8.214 are vulnerable to CVE-2026-41906.
What type of vulnerability is CVE-2026-41906?
CVE-2026-41906 is a Cross-Mailbox Authorization Bypass vulnerability that affects the Change Customer modal.
Who is impacted by CVE-2026-41906?
Users of FreeScout prior to version 1.8.214 are at risk of exploitation due to CVE-2026-41906.