BRIEFING NOTE: CVE-2026-40498 FreeScout versions prior to 1.8.213 contain a critical authentication bypass vulnerability affecting the /system/cron diagnostic endpoint. An unauthenticated attacker can access restricted administrative tools by exploiting a static MD5 hash derived from the application's APP_KEY, which is exposed in server responses and logs. This exposure of sensitive credentials combined with weak endpoint protection enables multiple attack vectors. The vulnerability carries a CVSS score of 9.8 (CRITICAL) with zero authentication requirements and network accessibility. Exploitation allows attackers to gain full confidentiality, integrity, and availability impact through three primary mechanisms: disclosure of sensitive server information including file paths and process IDs, resource exhaustion via repeated triggering of heavy background tasks, and potential brute-force attacks. The lack of rate limiting on affected endpoints significantly amplifies the risk of denial-of-service attacks. There is no evidence of active exploitation in the wild at this time. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, and no publicly disclosed exploit code is currently documented. Community attention remains limited, as reflected by an EPSS score of 0.0008 indicating low observed exploitation probability. Organizations running FreeScout should prioritize upgrading to version 1.8.213 or later to remediate this critical flaw before it becomes more widely disclosed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.213CPE matchmatch criteria | cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.