CVE-2026-35584: Freescout

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/{thread_id} does not require authentication and does not validate whether the given thread_id belongs to the given conversation_id. This allows any unauthenticated attacker to mark any thread as read by passing arbitrary IDs, enumerate valid thread IDs via HTTP response codes (200 vs 404), and manipulate opened_at timestamps across conversations (IDOR). This vulnerability is fixed in 1.8.212.

Affected products

  • Freescout Freescout: before 1.8.212 (fixed in 1.8.212)

Published 2026-04-07. Last modified 2026-06-17.