VULNERABILITY OVERVIEW CVE-2026-40569 is a mass assignment vulnerability affecting FreeScout, a free self-hosted help desk and shared mailbox platform, in versions prior to 1.8.213. The vulnerability exists in the mailbox connection settings endpoints where user input is passed directly to the model without field allowlisting, allowing authenticated administrators to overwrite security-critical mailbox fields not intended to be modified through the connection settings interface. SEVERITY ASSESSMENT The vulnerability carries a CVSS score of 9.0 (CRITICAL) with a network-based attack vector requiring high-level privileges (authenticated admin access) but no user interaction. The impact is severe: an authenticated attacker can inject hidden parameters to silently BCC outgoing emails to external accounts, redirect SMTP traffic through attacker-controlled servers, inject malicious content into email signatures, and enable fraudulent auto-replies. The attack is particularly dangerous because injected fields like "auto_bcc" are invisible on the connection settings form, allowing one administrator to covertly surveil mailboxes managed by others without detection. EXPLOITATION STATUS There is no indication of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog and is currently inactive on security hotlists. However, the attack requires only administrative access and a single HTTP request, making it relatively straightforward to exploit if an admin account is compromised through secondary vulnerabilities such as cross-site scripting. The persistence of email exfiltration after session expiry poses a significant post-compromise risk in multi-admin environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Freescout-Help-Desk | Freescout | < 1.8.213CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.