CVE-2026-40567
Last modified
CVE-2026-40567 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The name is stored in the database without sanitization and rendered unescaped into outgoing reply emails via the `{%customer.fullName%}` signature variable. This allows embedding phishing links, tracking pixels, and spoofed content inside legitimate support emails sent from the organization's address. Version 1.8.213 fixes the issue.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40567?
How severe is CVE-2026-40567?
How do I fix CVE-2026-40567?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40561Starlet versions through 0.31 for Perl allows HTTP Request S…5.3
- CVE-2026-40562Gazelle versions through 0.49 for Perl allows HTTP Request S…7.5
- CVE-2026-40563Description: Improper Control of Generation of Code ('Code I…8.1
- CVE-2026-40564Files or Directories Accessible to External Parties, Server-…6.5
- CVE-2026-40565FreeScout is a free self-hosted help desk and shared mailbox…6.1
- CVE-2026-40566FreeScout is a free self-hosted help desk and shared mailbox…4.1
- CVE-2026-40568FreeScout is a free self-hosted help desk and shared mailbox…8.5
- CVE-2026-40569FreeScout is a free self-hosted help desk and shared mailbox…9
- CVE-2026-4057The Download Manager plugin for WordPress is vulnerable to u…4.3
- CVE-2026-40570FreeScout is a free self-hosted help desk and shared mailbox…5.7
- CVE-2026-40571NamelessMC is website software for Minecraft servers. In ver…5.3
- CVE-2026-40572NovumOS is a custom 32-bit operating system written in Zig a…9
Are you affected by CVE-2026-40567?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
