Remote Code Execution Vulnerability in FreeScout Help Desk Software
CVE-2026-27636
8.8HIGH
What is CVE-2026-27636?
FreeScout, a popular help desk solution developed using the Laravel framework, has a vulnerability due to inadequate file upload restrictions. Specifically, versions before 1.8.206 allow authenticated users to upload .htaccess files. On Apache servers configured with AllowOverride All, this could enable the user to alter file processing rules, potentially leading to remote code execution. This risk exists independently or in conjunction with additional vulnerabilities. Users are encouraged to update to version 1.8.206 to mitigate this threat.
Affected Version(s)
freescout < 1.8.206
