PT-2026-33910 · Freescout · Freescout

CVE-2026-40496

·

Published

2026-04-21

·

Updated

2026-04-21

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.213
Description Attachment download tokens are generated using a weak and predictable formula: md5(APP KEY + attachment id + size). Because attachment id is sequential and size can be brute-forced within a small range, an unauthenticated attacker can forge valid tokens to download private attachments without credentials.
Recommendations Update to version 1.8.213.

Exploit

Fix

DoS

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40496
GHSA-2783-WXMM-WMWR

Affected Products

Freescout