Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40567

21
FAUCET Score

BRIEFING NOTE: CVE-2026-40567 OVERVIEW CVE-2026-40567 is an HTML injection vulnerability affecting FreeScout versions prior to 1.8.213, a free self-hosted help desk and shared mailbox platform. An unauthenticated attacker can inject arbitrary HTML into outgoing support emails by crafting a malicious From display name. The unsanitized input is stored in the database and rendered unescaped in reply emails through the customer full name signature variable, enabling attackers to embed phishing links, tracking pixels, and spoofed content within legitimate organizational communications. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.8 (Medium), reflecting a network-based attack requiring no authentication or user interaction. While the integrity impact is limited, the attack chain presents meaningful risk in the context of business email compromise. The attacker can leverage the trusted source of support emails to conduct targeted phishing campaigns against customers, potentially undermining organizational reputation and enabling secondary attacks. The FAUCET Risk Score of 33.0 out of 100 indicates moderate concern within the broader vulnerability landscape. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and the EPSS score of 0.00035 suggests minimal probability of exploitation in real-world scenarios. Patch availability through version 1.8.213 provides clear remediation. Community attention appears limited, indicating this is not a high-priority threat at this time.

Impacted Technologies

VendorProductVersion(s)CPE
Freescout-Help-DeskFreescout
< 1.8.213CNA affected

CVSS Data

CVSS version used by this source: 3.1

5.8MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 6th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / freescout-help-desk/freescout/commit/9131b16f80eade81002cb9809a2603f6b61981cf
github.com / freescout-help-desk/freescout/releases/tag/1.8.213
github.com / freescout-help-desk/freescout/security/advisories/GHSA-q8v4-v62h-5528