PT-2026-61701 · Freescout · Freescout

CVE-2026-53591

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.223
Description An unauthenticated attacker can inject messages into any existing support conversation by sending an email to the public helpdesk address containing a crafted In-Reply-To header. This action allows the attacker to insert messages that appear as legitimate customer replies in the agent user interface, automatically reopen the conversation, and update the last reply from field with the attacker's identity. No credentials or prior access are required for this exploitation.
Recommendations Update to version 1.8.223.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53591
GHSA-8VM3-WWQ4-GGFX

Affected Products

Freescout