Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-40569 โ€” AI Deep Analysis Summary

CVSS 9.0 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: FreeScout < 1.8.213 suffers from **Mass Assignment** in email connection settings.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **CWE-284**: Improper Control of Generation of Code ('Code Injection') / Mass Assignment. ๐Ÿ’ฅ **Flaw**: `connectionIncomingSave` & `connectionOutgoingSave` pass `$request->all()` directly to `$mailbox->fill`.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿข **Vendor**: FreeScout (Laravel PHP Help Desk). ๐Ÿ“ฆ **Affected**: Versions **before 1.8.213**. โœ… **Safe**: 1.8.213 and later. ๐Ÿ“… **Published**: 2026-04-21.

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Privileges**: Requires **Authenticated Admin** access. ๐ŸŽฏ **Impact**: Can modify **any fillable field** in the Mailbox model. ๐Ÿ“ฌ **Specifics**: Inject BCC addresses or hijack SMTP outgoing connections. ๐Ÿ”„

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”’ **Threshold**: **High** for Auth, **Low** for Execution. ๐Ÿ›‘ **PR:H**: Requires High Privileges (Admin). โšก **AC:L**: Low Complexity. ๐Ÿ–ฑ๏ธ **UI:N**: No User Interaction needed once logged in. ๐Ÿ“Š **CVSS**: High (8.1+).

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿšซ **Public Exp**: **No** public PoC or wild exploitation detected yet. ๐Ÿ“œ **Status**: POCs list is empty in data. ๐Ÿ” **Reference**: GHSA advisory confirms vulnerability but no exploit code shared. ๐Ÿ•ต๏ธโ€โ™‚๏ธ

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Check**: Scan for FreeScout instances. ๐Ÿ“‹ **Verify**: Check version number in footer/config. ๐Ÿ› ๏ธ **Feature**: Look for 'Connection Settings' endpoints.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: Yes! Patched in **v1.8.213**. ๐Ÿ”— **Commit**: `f45b9105d43b0352c08fcca154e8ae6177c3d860`. ๐Ÿ“ฅ **Action**: Upgrade immediately via GitHub releases. ๐Ÿš€

Q9What if no patch? (Workaround)

๐Ÿ›ก๏ธ **Workaround**: If stuck on old version, **restrict Admin access** strictly. ๐Ÿšซ **Mitigation**: Implement WAF rules to block mass-assignment payloads on `/connection/save` endpoints.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **HIGH**. ๐Ÿ“ข **Priority**: Patch immediately. โš ๏ธ **Reason**: Admin compromise leads to **data leakage** (BCC) and **service disruption** (SMTP redirect). ๐Ÿ“‰ **Risk**: Confidentiality & Integrity hit hard. ๐Ÿ›ก๏ธ