← العودة للجدول
CVE-2026-40496
CVE-2026-40496 — FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1
📅 2026-04-21
🔴 Critical 🔥 No NVD Exploit Phishing CVSS 9.1 🎯 EPSS 0.04%

📋 الوصف الكامل

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthenticated attacker can forge valid tokens and download any private attachment without credentials. Versi

💻 الأنظمة المتأثرة

FreeScout is a

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-40496

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.8.213

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←