CVE-2026-40589Disclosure

LOWCVSS 7.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address already owned by a hidden customer in another mailbox. The server discloses the hidden customer’s name and profile URL in the success flash, reassigns the hidden email to the visible customer, and rebinds hidden-mailbox conversations for that email to the visible customer. Version 1.8.214 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 2Technical Details · 2026-04-27: 204-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40589 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address al… https://www.cve.org/CVERecord?id=CVE-2026-40589 ----- Traducción: CVE-2026-40589 Fre… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑40589 for FreeScout, indicating that low‑privileged users can add email addresses in customers prior to version 1.8.214. No exploit, PoC, patch, or active‑exploitation details are provided.

    0000044
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40589 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address al… https://www.cve.org/CVERecord?id=CVE-2026-40589

    Post summary

    CVE‑2026‑40589 is a newly disclosed vulnerability in FreeScout that allows low‑privileged agents to modify a customer's email address; the post provides basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    00000167
    57.3K followersView on X

Explore more