Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-53595: FreeScout: Unauthenticated takeover of lowest-id user account
CVE-2026-53595
CVE-2026-53595
Summary
FreeScout, a free help desk and shared inbox, has a security flaw that allows an attacker to take over the account of the lowest-id user, potentially an administrator, without needing a password. This issue was fixed in version 1.8.224, so update to the latest version to protect your account. If you're unable to update, consider temporarily disabling the feature that allows users to invite others to join the help desk.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| freescout-help-desk | freescout | < 1.8.224 |
Original title
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetu...
Original description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_hash` column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets `invite_hash` to the empty string. On MySQL and MariaDB, `VARCHAR` equality ignores trailing spaces, so a single URL-encoded space (`%20`) matches the stored empty string and selects the lowest-id activated user. The expiry guard decrypts `invite_sent_at` with the target's password hash, but `Helper::decrypt` returns its raw input unchanged when decryption fails. A plaintext numeric value such as `9999999999` therefore passes the time-to-live check without any secret. The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. Version 1.8.224 contains a fix.
mitre CVSS3.1
9.4
Vulnerability type
CWE-178
CWE-287
Improper Authentication
CWE-640
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026