CVE-2026-40498Disclosure(freescout / freescout)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch freescout freescout systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in the response and logs. Accessing these endpoints reveals sensitive server information (Full Path Disclosure), process IDs, and allows for Resource Exhaustion (DoS) by triggering heavy background tasks repeatedly without any rate limiting. The cron hash is generated using md5(APP_KEY . 'web_cron_hash'). Since this hash is often transmitted via GET requests, it is susceptible to exposure in server logs, browser history, and proxy logs. Furthermore, the lack of rate limiting on these endpoints allows for automated resource exhaustion (DoS) and brute-force attempts. Version 1.8.213 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freescout

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
freescout

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-21: 2Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 204-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40498 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should… https://www.cve.org/CVERecord?id=CVE-2026-40498

    Post summary

    The post discloses that FreeScout versions prior to 1.8.213 allow unauthenticated attackers to access diagnostic tools, and the issue is mitigated in newer releases.

    01010124
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40498 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should… https://www.cve.org/CVERecord?id=CVE-2026-40498 ----- Traducción: FreeScout es una m… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-40498 in FreeScout, indicating unauthenticated access to diagnostic and system tools before v1.8.213, but does not provide evidence of active exploitation, patches, or PoC.

    0000022
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreescoutfreescout---

Explore more