Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41192

24
FAUCET Score

FreeScout, a free self-hosted help desk and shared mailbox platform, contains an insecure direct object reference vulnerability in versions prior to 1.8.215. The flaw exists in the reply and draft flows, which improperly trust client-supplied encrypted attachment IDs, allowing authenticated attackers to delete attachments belonging to other mailbox users by replaying encrypted IDs through the save_draft function. The vulnerability affects the integrity and availability of shared mailbox data, as attackers can remove attachments from conversations visible to them. The vulnerability has a CVSS score of 7.1 (HIGH) with a network attack vector requiring low complexity and user authentication but no user interaction. The impact is high for integrity (via unauthorized attachment deletion) and moderate for availability, while confidentiality remains unaffected. The EPSS score of 0.00034 indicates minimal current threat landscape prevalence relative to other vulnerabilities. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed in the CISA KEV catalog and has an inactive status on the hot list, suggesting limited community attention and low current exploitation risk. Organizations using FreeScout should prioritize upgrading to version 1.8.215 or later to remediate this privilege escalation and data destruction risk.

Impacted Technologies

VendorProductVersion(s)CPE
Freescout-Help-DeskFreescout
< 1.8.215CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 4th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / freescout-help-desk/freescout/commit/5f182818e2391f8e711fec6ae6648ac0b367bef5
github.com / freescout-help-desk/freescout/releases/tag/1.8.215
github.com / freescout-help-desk/freescout/security/advisories/GHSA-cv36-2j23-x6g3