CVE-2026-40589

7.6

FreeScout · FreeScout Help Desk

A low-privileged agent in FreeScout can perform an authorization bypass to reassign customer email addresses and conversations from hidden mailboxes to visible ones.

Executive summary

An authorization bypass vulnerability in FreeScout allows authenticated agents to gain unauthorized access to data in hidden mailboxes, posing a significant risk to customer privacy and data integrity.

Vulnerability

This flaw, categorized as CWE-639, allows a low-privileged authenticated agent to manipulate customer profiles and reassign email addresses. By triggering this authorization bypass, the attacker can force the application to rebind conversations from hidden mailboxes to visible customer profiles, resulting in the unauthorized disclosure of sensitive customer information.

Business impact

Successful exploitation of this vulnerability compromises the confidentiality and integrity of help desk operations. By accessing hidden customer profiles and conversations, an attacker can exfiltrate private data and disrupt communication workflows, leading to potential regulatory compliance violations and loss of customer trust. With a CVSS score of 7.6, this is a High severity issue that requires immediate attention to prevent unauthorized data exposure.

Remediation

Immediate Action: Update the FreeScout installation to version 1.8.214 or later to apply the necessary authorization checks.

Proactive Monitoring: Review audit logs for unusual agent activity, specifically looking for unexpected reassignments of customer email addresses or sudden access to hidden mailbox data.

Compensating Controls: Restrict permissions for agent accounts to the minimum level required for their role and implement strict access controls on sensitive mailbox configurations.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

The ability for an agent to bridge the gap between hidden and visible mailboxes represents a critical failure in data isolation. Administrators must prioritize updating to version 1.8.214 immediately to close this authorization gap and protect sensitive customer communications from unauthorized internal access.

Sources