Vulnerability Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-email validation. If the supplied email already belongs to a hidden customer, Customer::create() reuses that hidden customer object and fills empty profile fields from attacker-controlled input. Version 1.8.214 fixes the vulnerability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/freescout-help-desk/freescout/commit/b3d7611e6e173ed8a5e525b7
- https://github.com/freescout-help-desk/freescout/releases/tag/1.8.214
- https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wjw4-8
- https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wjw4-8
FAQ
What is CVE-2026-40590?
CVE-2026-40590 is a vulnerability with a CVSS score of 4.3 (MEDIUM). FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Un...
How severe is CVE-2026-40590?
CVE-2026-40590 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40590?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.