
CVE-2026-40590 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /cus… https://www.cve.org/CVERecord?id=CVE-2026-40590
Post summary
The text announces CVE-2026-40590, noting that before version 1.8.214 the Change Customer modal in FreeScout permits creating new customers through a specific POST endpoint, thereby disclosing a vulnerability.

