CVE-2026-48811: FreeScout: Thread Deletion Bypasses Mailbox Access Revocation
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's access to the mailbox containing the conversation has been revoked. The ThreadPolicy::delete authorization policy does not verify mailbox membership, so a former team member retains destructive write access to notes they created. This vulnerability is fixed in 1.8.221.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.221
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48811?
The severity of CVE-2026-48811 is rated as medium with a score of 4.3.
How do I fix CVE-2026-48811?
To fix CVE-2026-48811, you should update FreeScout to version 1.8.221 or later where the vulnerability is addressed.
What type of vulnerability is CVE-2026-48811?
CVE-2026-48811 is a vulnerability that allows non-admin users to bypass mailbox access revocation by permanently deleting internal notes.
What impact does CVE-2026-48811 have on my FreeScout installation?
CVE-2026-48811 could allow unauthorized users to delete private threads from conversations, potentially leading to data loss.
When was CVE-2026-48811 published?
CVE-2026-48811 was published on May 29, 2026.