CVE Explorer
CVE-2026-40496
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthenticated attacker can forge valid tokens and download any private attachment without credentials. Version 1.8.213 fixes the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-340","description":"CWE-340: Generation of Predictable Numbers or Identifiers","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-330","description":"CWE-330: Use of Insufficiently Random Values","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"freescout","vendor":"freescout-help-desk","versions":[{"status":"affected","version":"< 1.8.213"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-340","description":"CWE-340: Generation of Predictable Numbers or Identifiers","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-330","description":"CWE-330: Use of Insufficiently Random Values","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/freescout-help-desk/freescout/commit/dbdf8f2260b43a21818255c70f0b61b9de9cd555","tags":["x_refsource_MISC"],"url":"https://github.com/freescout-help-desk/freescout/commit/dbdf8f2260b43a21818255c70f0b61b9de9cd555"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/references/1
{"name":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.213","tags":["x_refsource_MISC"],"url":"https://github.com/freescout-help-desk/freescout/releases/tag/1.8.213"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/references/2
{"name":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-2783-wxmm-wmwr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-2783-wxmm-wmwr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:50d27ee9e6dbdb69c913f444139912f6e52b12ebd49aef89fed26cb5781f25d7 · sha256:7e438021e0d3aebf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.