PT-2026-34031 · Freescout · Freescout

CVE-2026-41191

·

Published

2026-04-21

·

Updated

2026-04-21

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.215
Description The MailboxesController::updateSave() function persists the chat start new variable outside the allowed-field filter. This allows a user who possesses only the mailbox sig permission to modify the hidden mailbox-wide chat setting through a direct POST request, despite the user interface only displaying the signature field.
Recommendations Update to version 1.8.215.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41191
GHSA-WPV9-C2GV-2J82

Affected Products

Freescout