Remote Code Execution Vulnerability in FreeScout Help Desk Software
CVE-2026-27636

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
25 February 2026

What is CVE-2026-27636?

FreeScout, a popular help desk solution developed using the Laravel framework, has a vulnerability due to inadequate file upload restrictions. Specifically, versions before 1.8.206 allow authenticated users to upload .htaccess files. On Apache servers configured with AllowOverride All, this could enable the user to alter file processing rules, potentially leading to remote code execution. This risk exists independently or in conjunction with additional vulnerabilities. Users are encouraged to update to version 1.8.206 to mitigate this threat.

Affected Version(s)

freescout < 1.8.206

References

EPSS Score

22% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.