Exposed Data in FreeScout Help Desk Software
CVE-2026-41183
4.3MEDIUM
What is CVE-2026-41183?
The FreeScout help desk software has a data exposure vulnerability that allows unauthorized access to conversations through its global search and AJAX filter paths. Prior to the release of version 1.8.215, the restriction meant for assigned-only users was not enforced in certain query cases, risking exposure of sensitive information. Users are encouraged to update to version 1.8.215 to mitigate this risk.
Affected Version(s)
freescout < 1.8.215
