CVE-2026-53595: FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint POST /user-setup/{hash}/{invitesentat} (OpenController@userSetupSave) selects the target account solely by its invitehash column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets invitehash to the empty string. On MySQL and MariaDB, VARCHAR equality ignores trailing spaces, so a single URL-encoded space (%20) matches the stored empty string and selects the lowest-id activated user. The expiry guard decrypts invitesentat with the target's password hash, but Helper::decrypt returns its raw input unchanged when decryption fails. A plaintext numeric value such as 9999999999 therefore passes the time-to-live check without any secret. The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. Version 1.8.224 contains a fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeScoutto a version that resolves this vulnerability.Fixed in 1.8.224 - Operational
After upgrading to 1.8.224, rotate credentials for any FreeScout accounts that may have been taken over via the unauthenticated POST /user-setup/{hash}/{invite_sent_at} endpoint (attack can overwrite email/password and authenticate as the compromised account).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53595?
CVE-2026-53595 has a critical severity rating of 9.4.
How do I fix CVE-2026-53595?
To fix CVE-2026-53595, upgrade FreeScout to version 1.8.224 or later.
What is the risk associated with CVE-2026-53595?
The risk associated with CVE-2026-53595 is rated at 76, indicating a significant impact.
Can CVE-2026-53595 allow unauthorized access?
Yes, CVE-2026-53595 allows for anonymous account takeover due to a vulnerability in the user setup functionality.
What kind of accounts are affected by CVE-2026-53595?
CVE-2026-53595 affects accounts that can be accessed via the `/user-setup` endpoint using an empty `invite_hash`.