CVE-2026-48812: FreeScout Allows Unauthenticated Access to Legacy Attachment Files
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose tokentype is set to 1 (TOKENTYPELEGACY). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was created by an older version of FreeScout without possessing a valid token or session. Version 1.8.221 contains a fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.221
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48812?
CVE-2026-48812 has a severity score of 7.5, indicating it is a high-risk vulnerability.
How do I fix CVE-2026-48812?
To fix CVE-2026-48812, upgrade FreeScout to version 1.8.221 or later.
What does CVE-2026-48812 exploit?
CVE-2026-48812 exploits a vulnerability in FreeScout that allows unauthenticated access to legacy attachment files.
Which versions of FreeScout are affected by CVE-2026-48812?
FreeScout versions prior to 1.8.221 are affected by CVE-2026-48812.
What type of access does CVE-2026-48812 allow?
CVE-2026-48812 allows unauthenticated users to download legacy attachment files without authentication.