HarborGuard / CVE
Back to search
HIGHCVE-2026-40496Published Modified CNA GitHub_M

CVE-2026-40496: FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthenticated attacker can forge valid tokens and download any private attachment without credentials. Version 1.8.213 fixes the issue.

Metrics

CVSS v4.0
8.8
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • freescout-help-desk / freescout
    < 1.8.213
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
CVE-2026-40496: FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force | HarborGuard CVE