CVE-2026-39384Disclosure(freescout / freescout)

LOWCVSS 7.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-07: 2Technical Details · 2026-04-07: 204-07
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39384 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parame… https://www.cve.org/CVERecord?id=CVE-2026-39384 ----- Traducción: CVE-2026-39384 Fre… http://infoflow.cloud`

    Post summary

    The message alerts about CVE‑2026‑39384 in FreeScout, giving a brief technical note on the affected parameter and linking to the official CVE record.

    0000033
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-39384 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parame… https://www.cve.org/CVERecord?id=CVE-2026-39384

    Post summary

    The post references CVE-2026-39384 and outlines an affected parameter in older FreeScout releases, but provides no PoC, exploit, or patch information.

    00000153
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more