CVE-2026-40496Disclosure(freescout / freescout)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthenticated attacker can forge valid tokens and download any private attachment without credentials. Version 1.8.213 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-330CWE-340

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-24: 1Technical Details · 2026-04-21: 104-2104-24
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-241
General1
Full discourse2 posts
  • z3n@zench4n
    General

    Don't overlook the middleware layer. New CVEs in PJSIP (CVE-2026-40892) and FreeScout (CVE-2026-40496) highlight how legacy communication and help desk libraries remain prime targets for lateral movement in enterprise environments.

    Post summary

    The post announces new CVEs in PJSIP and FreeScout, noting their potential for lateral movement in enterprises, but offers no technical, exploit, or remediation details.

    1001047
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40496 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula:… https://www.cve.org/CVERecord?id=CVE-2026-40496

    Post summary

    A new vulnerability (CVE-2026-40496) in FreeScout’s attachment token logic has been disclosed, noting that pre‑1.8.213 tokens use a weak, predictable generation method.

    0000059
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more