CVE-2026-41192Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted attachment IDs. Any IDs present in `attachments_all[]` but omitted from retained lists are decrypted and passed directly to `Attachment::deleteByIds()`. Because `load_attachments` returns encrypted IDs for attachments on a visible conversation, a mailbox peer can replay those IDs through `save_draft` and delete the original attachment row and file. Version 1.8.215 fixes the vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 104-2104-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-221
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41192 Arbitrary File Deletion in FreeScout Prior to Version 1.8.215 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41192 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces CVE‑2026‑41192, a file‑deletion vulnerability affecting FreeScout versions before 1.8.215, and provides links to further details, but no exploit, PoC, or patch information.

    0000050
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41192 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted attachment IDs. Any … https://www.cve.org/CVERecord?id=CVE-2026-41192 ----- Traducción: CVE-2026-41192 Fre… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑41192 affecting FreeScout versions below 1.8.215 due to trusting client‑supplied encrypted attachment IDs, with no PoC, exploit, or patch information provided.

    0000027
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41192 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted attachment IDs. Any … https://www.cve.org/CVERecord?id=CVE-2026-41192

    Post summary

    The text summarizes the vulnerability disclosed in CVE‑2026‑41192, highlighting how FreeScout’s reply and draft flows incorrectly trust client‑supplied encrypted attachment IDs prior to version 1.8.215. It provides technical details but no PoC, exploit code, active exploitation, or patch/workaround information.

    00000163
    57.2K followersView on X

Explore more