CVE-2026-27637Disclosure(freescout / freescout)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freescout freescout systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is static (never expires/rotates), and if an attacker obtains the `APP_KEY` — a well-documented and common exposure vector in Laravel applications — they can compute a valid token for any user, including the administrator, achieving full account takeover without any password. This vulnerability can be exploited on its own or in combination with CVE-2026-27636. Version 1.8.206 fixes both vulnerabilities.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-330

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 7 mentions (2026-02-25); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline9 mentions / 3d
02457Mentions · 2026-02-25: 7Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 3Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-25: 7Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 102-2502-2603-02
Signal classification2 categories
Disclosure
666.7%
Patch
333.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-257
Disclosure5Patch2
2026-02-261
Patch1
2026-03-021
Disclosure1
Full discourse9 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Two critical vulnerabilities in #FreeScout help desk. #CVE-2026-27636 and #CVE-2026-27637 can be exploited independently or chained together to achieve remote code execution #RCE! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-freescout-could-be-exploited-achieve-remote-code #Patch #Patch #Patch

    Post summary

    The advisory warns of two critical CVEs in FreeScout that enable remote code execution, and indicates that patches are available.

    02010273
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 FreeScout CVE-2026-27636 Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc CVE-2026-27637 Predictable Authentication Token Enables Account Takeover https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6gcm-v8xf-j9v9

    Post summary

    The post lists two new CVEs for FreeScout with brief vulnerability descriptions and links to GitHub advisories, but no PoC, exploit, or patch details are provided.

    01010432
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27637 Authentication Token Bypass in FreeScout Prior to Version 1.8.206 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27637

    Post summary

    The text announces a new authentication token bypass vulnerability in FreeScout before version 1.8.206, with no evidence of exploitation or mitigation.

    0001043
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27637 (CVSS:9.8, CRITICAL) is Analyzed. FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's..https://nvd.nist.gov/vuln/detail/CVE-2026-27637 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical vulnerability (CVE-2026-27637) in FreeScout before version 1.8.206, noting its CVSS score but providing no exploit or mitigation details.

    0000035
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A predictable authentication token vulnerability (CVE-2026-27637) impacts `FreeScout` leading to account takeover risk. Apply the available patch. #infosec #security #freescout https://www.pulsepatch.io/posts/cve-2026-27637-freescout-predictable-auth-token-vulnerability

    Post summary

    The post announces a predictable authentication token vulnerability in FreeScout (CVE-2026-27637) and urges users to apply the available patch to mitigate account takeover risk.

    0000052
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27637 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable aut… https://www.cve.org/CVERecord?id=CVE-2026-27637

    Post summary

    The post announces CVE‑2026‑27637, noting that FreeScout’s TokenAuth middleware uses a predictable authentication mechanism prior to version 1.8.206, but provides no PoC, exploit, or patch details.

    00000109
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: FreeScout <1.8.206 lets attackers generate admin tokens if APP_KEY leaks — full account takeover possible! Patch now. 🔒 https://radar.offseq.com/threat/cve-2026-27637-cwe-330-use-of-insufficiently-rando-8f97b2e6 #OffSeq #Infosec #Vulnerability https://t.co/4IE4BkHLOC

    Post summary

    FreeScout versions below 1.8.206 allow attackers to generate admin tokens if the APP_KEY leaks, enabling full account takeover; patch immediately.

    0000060
    270 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27637: CRITICAL] Vulnerability alert: FreeScout versions before 1.8.206 have a predictable auth token issue due to MD5 usage. Upgrade to secure systems from possible account takeovers.#cve,CVE-2026-27637,#cybersecurity https://cvefind.com/CVE-2026-27637

    Post summary

    A critical auth token vulnerability in FreeScout versions prior to 1.8.206 is highlighted, with a recommendation to upgrade to mitigate potential account takeovers.

    0000059
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-27637 pertains to a critical security flaw in FreeScout versions prior to 1.8.206. The core issue lies in the implementation of the `TokenAuth` middleware, which generates authentication tokens based on a predictable pattern: `MD5(user_id + created_at + APP_KEY)`. These tokens are static, meaning they do not expire or rotate over time. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-27637

    Post summary

    The post discloses a critical flaw in FreeScout's TokenAuth middleware that generates predictable, static tokens, potentially enabling privilege escalation.

    0000040
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more