← Back to CVEs
CVE-2026-40570
N/ADescription
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` returns complete customer profile data to any authenticated user without verifying mailbox access. An attacker only needs a valid email address to retrieve all customer PII. Version 1.8.213 fixes the issue.
CVE Details
CVSS v3.1 ScoreN/A
Published4/21/2026
Last Modified4/22/2026
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-639CWE-862
References
https://github.com/freescout-help-desk/freescout/commit/f35b4249c72d9bdac6ab1ea4e288f5894be34057(security-advisories@github.com)
https://github.com/freescout-help-desk/freescout/releases/tag/1.8.213(security-advisories@github.com)
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-w77q-wjfp-c822(security-advisories@github.com)
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-w77q-wjfp-c822(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.