Email Processing Vulnerability in FreeScout by FreeScout
CVE-2026-47123

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-47123?

FreeScout, a help desk and shared inbox solution developed with the Laravel framework, suffers from a vulnerability in its email processing pipeline. This issue arises in the FetchEmails command prior to version 1.8.220, where the extraction of agent replies is performed without adequate HMAC verification. An attacker capable of spoofing a help desk agent's From address can craft malicious messages. These messages can be erroneously processed as legitimate replies, leading to unauthorized communication being forwarded to customers via the SMTP server. The vulnerability is addressed in version 1.8.220.

Affected Version(s)

freescout < 1.8.220

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.