CVE-2026-53595
FreeScout, a free help desk built on Laravel, had a critical flaw that let anyone change the email and password of the lowest‑ID activated account and log in as that user. The vulnerability existed before version 1.8.224 and was fixed in that release. No authentication was required to exploit it.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
FreeScout installations running any version earlier than 1.8.224, especially those with activated support or admin accounts.
Real-world impact
An attacker could hijack an existing support or administrator account, gaining full access to the help desk, sensitive customer data, and the ability to modify or delete tickets.
Why this severity
The CVSS score of 9.4 reflects that the flaw is exploitable over the network, requires no privileges, and allows complete compromise of confidentiality and integrity of the system. The high impact on confidentiality and integrity, combined with the low effort required, drives the critical rating.
What to do about it
- 011. Upgrade FreeScout to version 1.8.224 or later.
- 022. Restart the service if necessary.
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.