CVE-2026-53591: FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted In-Reply-To header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the lastreplyfrom field is set to the attacker's identity. Version 1.8.223 contains a fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.223
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53591?
CVE-2026-53591 has a high severity rating of 8.6.
How do I fix CVE-2026-53591?
To fix CVE-2026-53591, upgrade FreeScout to version 1.8.223 or later.
What type of attack does CVE-2026-53591 involve?
CVE-2026-53591 involves unauthenticated conversation thread injection via a crafted `In-Reply-To` header.
Which software is affected by CVE-2026-53591?
FreeScout prior to version 1.8.223 is affected by CVE-2026-53591.
What is the impact of CVE-2026-53591?
CVE-2026-53591 allows an unauthenticated attacker to inject messages into existing support conversations.