Unauthenticated Message Injection in FreeScout Help Desk Software
CVE-2026-53591

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-53591?

The FreeScout help desk software, built on the Laravel framework, is subject to a message injection vulnerability. Prior to version 1.8.223, an unauthenticated attacker can exploit this flaw by sending a specially crafted email to the helpdesk's public address. This allows the attacker to inject messages into existing support conversations without needing any credentials or prior access. The injected message appears as a legitimate response from a customer, reopening the conversation and altering the last_reply_from field to reflect the attacker's identity. This vulnerability underscores the importance of updating to version 1.8.223 to maintain the integrity of communications and security within your support channels.

Affected Version(s)

freescout < 1.8.223

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.