BRIEFING NOTE: CVE-2026-40567 OVERVIEW CVE-2026-40567 is an HTML injection vulnerability affecting FreeScout versions prior to 1.8.213, a free self-hosted help desk and shared mailbox platform. An unauthenticated attacker can inject arbitrary HTML into outgoing support emails by crafting a malicious From display name. The unsanitized input is stored in the database and rendered unescaped in reply emails through the customer full name signature variable, enabling attackers to embed phishing links, tracking pixels, and spoofed content within legitimate organizational communications. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.8 (Medium), reflecting a network-based attack requiring no authentication or user interaction. While the integrity impact is limited, the attack chain presents meaningful risk in the context of business email compromise. The attacker can leverage the trusted source of support emails to conduct targeted phishing campaigns against customers, potentially undermining organizational reputation and enabling secondary attacks. The FAUCET Risk Score of 33.0 out of 100 indicates moderate concern within the broader vulnerability landscape. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and the EPSS score of 0.00035 suggests minimal probability of exploitation in real-world scenarios. Patch availability through version 1.8.213 provides clear remediation. Community attention appears limited, indicating this is not a high-priority threat at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Freescout-Help-Desk | Freescout | < 1.8.213CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.