
CVE-2026-40591 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`… https://www.cve.org/CVERecord?id=CVE-2026-40591
Post summary
The post references CVE-2026-40591, noting a flaw in FreeScout's phone-conversation creation flow that accepts attacker-controlled `customer_id`, but provides no further details on exploitation, mitigation, or evidence of active attacks.

