Junglewise Threat Intelligence

CVE-2026-45295: FreeScout authorization bypass in open tracking endpoint

CVE-2026-45295 · Severity: medium · CVSS 6.5 · Published 2026-07-20

Technologies: FreeScout Help Desk FreeScout. Vendors: FreeScout Help Desk.

Executive brief

FreeScout is an open-source help desk and shared inbox platform. A security flaw in the email tracking system allows unauthorized individuals to identify valid support conversation IDs and tamper with "read" timestamps. This can lead to the corruption of communication analytics and provide a starting point for further unauthorized access to customer support data.

Technical details

An authorization bypass exists in the FreeScout open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` within `app/Http/Controllers/OpenController.php`. The endpoint, intended to serve a 1x1 tracking pixel, lacks authentication and session checks. Because the server returns a 200 OK for valid ID pairs and a 404 Not Found for invalid ones, an unauthenticated attacker can use a side-channel timing or response oracle to enumerate valid conversation and thread IDs. Furthermore, accessing the endpoint automatically updates the `opened_at` timestamp in the database, allowing attackers to manipulate thread read-status data. The issue is resolved in version 1.8.219.

Affected products

  • freescout-help-desk FreeScout < 1.8.219

Timeline

  • 2026-05-17: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: NVD publication date

References