CVE-2026-41902General

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration check — the hash remains valid indefinitely until consumed. Combined with realistic hash-leakage scenarios (forwarded invite emails, HTTP referrer to external CDNs on the setup page, server-side log exposure, abandoned invite emails in shared inboxes), this enables unauthenticated permanent account takeover months or years after invite issuance. If the leaked invite was sent to an admin, the takeover yields admin access. This issue has been patched in version 1.8.217.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • General: 5 classified signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 3 mentions (2026-05-07); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-08: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 3Mentions · 2026-05-20: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-07: 3Technical Details · 2026-05-08: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 205-0705-0805-1105-1305-20
Signal classification3 categories
General
555.6%
Disclosure
333.3%
Patch
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure2General1
2026-05-081
Disclosure1
2026-05-111
Patch1
2026-05-133
General3
2026-05-201
General1
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-41902 · 9.1 → 1.8.217 CVE: CVE-2026-41902 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The snippet provides a critical advisory with CVSS details for CVE-2026-41902 but lacks any proof‑of‑concept, exploit code, or mitigation instructions.

    1000045
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-41902 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory FreeScout is a free help desk and shared inbox built with PHP's Laravel framework.

    Post summary

    The text announces CVE-2026-41902 as a critical vulnerability with CVSS details but provides no proof of concept, exploit code, active exploitation evidence, or patch information.

    1000060
    210 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-41902 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-… CVSS 9.1 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-41902 #HP #CyberSecurity #InfoSec

    Post summary

    Critical CVE-2026-41902 affects FreeScout prior to v1.8.217; CVSS 9.1, no patch currently available, and a detailed analysis is provided via the external link.

    0001052
    515 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41902 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character ra… https://www.cve.org/CVERecord?id=CVE-2026-41902

    Post summary

    The post reports a vulnerability in FreeScout’s /user-setup/{hash} endpoint before version 1.8.217, noting a 60‑character input but providing no PoC or exploit details.

    00010215
    57.4K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-41902: FreeScout Invitation Hash Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04hhh150

    Post summary

    The article announces a FreeScout invitation hash flaw but does not provide technical details, a PoC, or evidence of exploitation.

    0000039
    31 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41902-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text consists only of a link and hashtags, lacking substantive details about the CVE.

    0000024
    210 followersView on X
  • Polsia@polsia
    Patch

    CVE-2026-41902: FreeScout's /user-setup endpoint never expires password reset hashes. CVSS 9.1. Attackers reset any account indefinitely. Upgrade to 1.8.217. https://threatforge-l929.polsia.app

    Post summary

    The post alerts readers to FreeScout CVE-2026-41902, a high‑severity flaw that allows indefinite password resets because the /user‑setup endpoint never expires hashes, and advises updating to version 1.8.217.

    0000034
    18.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41902 Unauthenticated Account Takeover via Non-Expiring Invite Hash in FreeScout Before 1.8.217 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41902

    Post summary

    The text announces the discovery of an unauthenticated account takeover vulnerability in FreeScout versions prior to 1.8.217, providing basic technical details but no proof of exploitation or mitigation steps.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-41902 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character ra… https://www.cve.org/CVERecord?id=CVE-2026-41902 ----- Traducción: CVE-2026-41902 Fre… http://infoflow.cloud`

    Post summary

    The post identifies CVE‑2026‑41902 and notes that the /user‑setup/{hash} endpoint is vulnerable prior to a specific version, with no mention of PoC, exploit, active use, patch, or false‑positive claims.

    0000040
    75 followersView on X

Explore more