Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40569

30
FAUCET Score

VULNERABILITY OVERVIEW CVE-2026-40569 is a mass assignment vulnerability affecting FreeScout, a free self-hosted help desk and shared mailbox platform, in versions prior to 1.8.213. The vulnerability exists in the mailbox connection settings endpoints where user input is passed directly to the model without field allowlisting, allowing authenticated administrators to overwrite security-critical mailbox fields not intended to be modified through the connection settings interface. SEVERITY ASSESSMENT The vulnerability carries a CVSS score of 9.0 (CRITICAL) with a network-based attack vector requiring high-level privileges (authenticated admin access) but no user interaction. The impact is severe: an authenticated attacker can inject hidden parameters to silently BCC outgoing emails to external accounts, redirect SMTP traffic through attacker-controlled servers, inject malicious content into email signatures, and enable fraudulent auto-replies. The attack is particularly dangerous because injected fields like "auto_bcc" are invisible on the connection settings form, allowing one administrator to covertly surveil mailboxes managed by others without detection. EXPLOITATION STATUS There is no indication of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog and is currently inactive on security hotlists. However, the attack requires only administrative access and a single HTTP request, making it relatively straightforward to exploit if an admin account is compromised through secondary vulnerabilities such as cross-site scripting. The persistence of email exfiltration after session expiry poses a significant post-compromise risk in multi-admin environments.

Impacted Technologies

VendorProductVersion(s)CPE
Freescout-Help-DeskFreescout
< 1.8.213CNA affected

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 3rd percentile among its peer group of 464 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / freescout-help-desk/freescout/commit/f45b9105d43b0352c08fcca154e8ae6177c3d860
github.com / freescout-help-desk/freescout/releases/tag/1.8.213
github.com / freescout-help-desk/freescout/security/advisories/GHSA-hmqm-33wp-858j