Junglewise Threat Intelligence

CVE-2026-47123: FreeScout agent impersonation via missing HMAC in notification replies

CVE-2026-47123 · Severity: high · CVSS 7.5 · Published 2026-05-29

Technologies: FreeScout Help Desk FreeScout. Vendors: FreeScout Help Desk.

Executive brief

FreeScout is an open-source help desk and shared inbox platform. A security flaw in how the system processes incoming emails allows an attacker to impersonate a help desk agent. By sending a specially crafted email, an attacker can inject messages into existing support threads that appear to be legitimate replies from staff. These forged messages are then automatically forwarded to customers through the organization's official email server, which could be used to conduct highly convincing phishing attacks or distribute malicious links under the guise of official support.

Technical details

The vulnerability exists in the `FetchEmails` command's `processMessage()` function. While the customer reply path correctly implements HMAC verification using the `APP_KEY`, the notification reply path (`notify-{thread_id}-{user_id}-...`) extracts the `thread_id` and `user_id` directly from the `In-Reply-To` or `References` headers without any cryptographic verification. An attacker who knows a valid `thread_id` and an agent's email address can spoof the `From` address and craft a `Message-ID` that matches the vulnerable regex. Because FreeScout does not perform SPF/DKIM/DMARC validation on incoming mail, it processes these forged emails as legitimate agent replies and triggers the `UserReplied` event, causing the `SendReplyToCustomer` job to forward the attacker's content to the customer via the legitimate SMTP server. This issue is fixed in version 1.8.220.

Affected products

  • FreeScout FreeScout < 1.8.220

Timeline

  • 2026-05-19: advisory: GitHub Security Advisory GHSA-6r38-6mcf-2ww3 published
  • 2026-05-29: disclosed: CVE-2026-47123 published to NVD
  • 2026-05-29: patched: Fix released in version 1.8.220

References

Related threats