PT-2026-44993 · Freescout · Freescout

·

CVE-2026-47123

·

Published

2026-05-29

·

Updated

2026-07-22

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.220
Description The email processing pipeline in the FetchEmails command contains two code paths for identifying agent replies using In-Reply-To and References headers. The notification reply path (notify-thread id-user id-...) extracts the thread id and user id directly from the Message-ID without HMAC (Hash-based Message Authentication Code) verification. This allows an external attacker to spoof the From address of a helpdesk agent and inject messages that are processed as legitimate agent replies, which are then automatically forwarded to customers via the legitimate SMTP server.
Recommendations Update to version 1.8.220.

Exploit

Fix

Authentication Bypass by Spoofing

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47123
GHSA-6R38-6MCF-2WW3

Affected Products

Freescout