Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026
FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVE-2026-45295
Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint GET /thread/read/{conversation_id}/{thread_id} allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (opened_at timestamp) without any authentication. Version 1.8.219 patches the issue.
Affected products
1Patches
Vulnerability mechanics
References
1- github.com/freescout-help-desk/freescout/security/advisories/GHSA-qjr9-6v9q-3r72mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.