Email Enumeration Vulnerability in FreeScout Help Desk
CVE-2026-45294

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-45294?

FreeScout, a PHP-based help desk solution, has a vulnerability in its password reset functionality that allows unauthenticated parties to identify valid email addresses associated with user accounts. Specifically, the system provides differing responses based on the existence of an email in its database. This can lead to unauthorized users compiling a list of valid helpdesk agent emails, heightening the risk of targeted attacks. The issue has been remedied in the 1.8.219 update.

Affected Version(s)

freescout < 1.8.219

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.