CVE-2026-45295

Summary

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint GET /thread/read/{conversation_id}/{thread_id} allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (opened_at timestamp) without any authentication. Version 1.8.219 patches the issue.

Affected Software

VendorProductVersion RangeStatus
freescout-help-deskfreescout< 1.8.219affected

Weaknesses

  • CWE-639: CWE-639: Authorization Bypass Through User-Controlled Key
  • CWE-862: CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References