CVE-2026-48812: Freescout-Help-Desk Freescout
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was created by an older version of FreeScout without possessing a valid token or session. Version 1.8.221 contains a fix.
Affected products
- Freescout-Help-Desk Freescout: before 1.8.221 (fixed in 1.8.221)
Published 2026-07-20. Last modified 2026-07-21.