CVE-2026-39384
7.6FreeScout · Help Desk
FreeScout contains an authorization bypass vulnerability in the customer merging process, allowing authenticated users to manipulate data due to an ignored security parameter.
Executive summary
FreeScout versions prior to 1.8.212 are vulnerable to an authorization bypass that could allow authenticated users to improperly merge customer data.
Vulnerability
This is an authorization bypass flaw (CWE-639) where the application fails to validate the limit_user_customer_visibility parameter during customer merge operations, requiring low-privileged authenticated access to exploit.
Business impact
Successful exploitation of this flaw allows an authenticated user to bypass intended authorization controls, potentially leading to unauthorized data modification or exposure of sensitive customer information. With a CVSS score of 7.6, this vulnerability represents a high risk to data integrity within the help desk environment, which may result in significant operational disruption or compliance concerns.
Remediation
Immediate Action: Update the FreeScout installation to version 1.8.212 or later to apply the necessary security patch.
Proactive Monitoring: Review audit logs for suspicious customer merge activity or unauthorized account modifications.
Compensating Controls: Implement strict access control lists and review user permissions within the help desk to ensure that only authorized personnel can perform sensitive administrative tasks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized data manipulation and the existence of a proof-of-concept, administrators should prioritize updating FreeScout to version 1.8.212. Applying this patch is the most effective way to remediate the authorization flaw and prevent potential data integrity compromises.