Email Processing Vulnerability in FreeScout by FreeScout
CVE-2026-47123
7.5HIGH
What is CVE-2026-47123?
FreeScout, a help desk and shared inbox solution developed with the Laravel framework, suffers from a vulnerability in its email processing pipeline. This issue arises in the FetchEmails command prior to version 1.8.220, where the extraction of agent replies is performed without adequate HMAC verification. An attacker capable of spoofing a help desk agent's From address can craft malicious messages. These messages can be erroneously processed as legitimate replies, leading to unauthorized communication being forwarded to customers via the SMTP server. The vulnerability is addressed in version 1.8.220.
Affected Version(s)
freescout < 1.8.220
