Unauthenticated Access Vulnerability in FreeScout Help Desk by FreeScout
CVE-2026-45295
6.5MEDIUM
What is CVE-2026-45295?
FreeScout, a free help desk application built on the Laravel framework, contains a vulnerability that permits unauthenticated attackers to exploit the open tracking endpoint. Specifically, this enables attackers to enumerate valid conversation and thread IDs through the GET /thread/read/{conversation_id}/{thread_id} endpoint, as well as modify the state of threads by altering the opened_at timestamp. This vulnerability is resolved in version 1.8.219.
Affected Version(s)
freescout < 1.8.219
