CVE-2026-53595: FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL

Published Jul 20, 2026
·
Updated

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint POST /user-setup/{hash}/{invitesentat} (OpenController@userSetupSave) selects the target account solely by its invitehash column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets invitehash to the empty string. On MySQL and MariaDB, VARCHAR equality ignores trailing spaces, so a single URL-encoded space (%20) matches the stored empty string and selects the lowest-id activated user. The expiry guard decrypts invitesentat with the target's password hash, but Helper::decrypt returns its raw input unchanged when decryption fails. A plaintext numeric value such as 9999999999 therefore passes the time-to-live check without any secret. The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. Version 1.8.224 contains a fix.

Affected Software

1 affected component
FreeScout<1.8.224

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeScout to a version that resolves this vulnerability.

    Fixed in 1.8.224
  2. Operational

    After upgrading to 1.8.224, rotate credentials for any FreeScout accounts that may have been taken over via the unauthenticated POST /user-setup/{hash}/{invite_sent_at} endpoint (attack can overwrite email/password and authenticate as the compromised account).

Event History

Jul 20, 2026
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-53595?

CVE-2026-53595 has a critical severity rating of 9.4.

2

How do I fix CVE-2026-53595?

To fix CVE-2026-53595, upgrade FreeScout to version 1.8.224 or later.

3

What is the risk associated with CVE-2026-53595?

The risk associated with CVE-2026-53595 is rated at 76, indicating a significant impact.

4

Can CVE-2026-53595 allow unauthorized access?

Yes, CVE-2026-53595 allows for anonymous account takeover due to a vulnerability in the user setup functionality.

5

What kind of accounts are affected by CVE-2026-53595?

CVE-2026-53595 affects accounts that can be accessed via the `/user-setup` endpoint using an empty `invite_hash`.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203