CVE-2026-40569 - Vulnerability Analysis
CriticalCVSS: 9.0Last Updated: April 21, 2026
FreeScout - Broken Access Control
Overview
FreeScout < 1.8.213 contains a mass assignment vulnerability caused by lack of field allowlisting in mailbox connection settings endpoints, letting authenticated admins silently manipulate mailbox fields to exfiltrate emails or redirect SMTP, exploit requires authenticated admin privileges.
Severity & Score
Impact
Authenticated admins can silently exfiltrate emails, redirect SMTP, or inject malicious content, compromising confidentiality and integrity of mailbox communications.
Mitigation
Upgrade to version 1.8.213 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-40569 - Critical (9) FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesCo... š https://www.thehackerwire.com/vulnerability/CVE-2026-40569/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-40569
- Severity
- Critical
- CVSS Score
- 9.0
- Type
- broken_access_control
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 1
CWE
- CWE-284
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L