Email Enumeration Vulnerability in FreeScout Help Desk
CVE-2026-45294
5.3MEDIUM
What is CVE-2026-45294?
FreeScout, a PHP-based help desk solution, has a vulnerability in its password reset functionality that allows unauthenticated parties to identify valid email addresses associated with user accounts. Specifically, the system provides differing responses based on the existence of an email in its database. This can lead to unauthorized users compiling a list of valid helpdesk agent emails, heightening the risk of targeted attacks. The issue has been remedied in the 1.8.219 update.
Affected Version(s)
freescout < 1.8.219
