CVE-2026-41904

7.6

FreeScout · FreeScout Help Desk

A stored cross-site scripting vulnerability in FreeScout prior to version 1.8.217 allows authenticated users with updateAutoReply permissions to inject malicious payloads into auto-reply messages.

Executive summary

A stored cross-site scripting vulnerability in FreeScout affects versions prior to 1.8.217, creating significant risks of client-side code execution for customers receiving automated emails.

Vulnerability

This is a stored cross-site scripting flaw classified under CWE-79, triggered when an authenticated user with updateAutoReply permissions stores a malicious payload that executes in the context of the customer's webmail client.

Business impact

A successful exploit allows attackers to execute arbitrary scripts within the email clients of customers who contact the help desk. This can lead to unauthorized actions, session hijacking, or data exfiltration via the victim mail client. The CVSS score of 7.6 reflects a high severity level due to the potential for confidentiality and integrity impacts against external users.

Remediation

Immediate Action: Update FreeScout to version 1.8.217 or later where this vulnerability has been patched.

Proactive Monitoring: Review administrative audit logs for suspicious modifications to auto-reply messages or unusual privilege assignments.

Compensating Controls: Enforce strict access controls to limit the updateAutoReply permission exclusively to trusted administrative accounts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing FreeScout should prioritize upgrading to version 1.8.217 immediately to eliminate the underlying cross-site scripting flaw. Reviewing user permissions to ensure strict adherence to the principle of least privilege will further reduce the likelihood of unauthorized payload injection.

Sources