Remote Code Execution Vulnerability in FreeScout Help Desk Software
CVE-2026-27636
8.8HIGH
What is CVE-2026-27636?
FreeScout, a popular help desk solution developed using the Laravel framework, has a vulnerability due to inadequate file upload restrictions. Specifically, versions before 1.8.206 allow authenticated users to upload .htaccess files. On Apache servers configured with AllowOverride All, this could enable the user to alter file processing rules, potentially leading to remote code execution. This risk exists independently or in conjunction with additional vulnerabilities. Users are encouraged to update to version 1.8.206 to mitigate this threat.
Affected Version(s)
freescout < 1.8.206
References
EPSS Score
22% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
