PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107393 freescout-help-desk CVE debrief

FreeScout, a self-hosted help desk and shared mailbox, had a stored HTML injection vulnerability prior to version 1.8.235. When the APP_CLOUDFLARE_IS_USED setting is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts. The spoofed value is stored in the activity log and, without HTML escaping, is inserted into administrator alert emails by LogsMonitor. This allows injected HTML to execute when an administrator opens the email.

Vendor
freescout-help-desk
Product
freescout
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for FreeScout instances, especially those using versions prior to 1.8.235, should assess their exposure and take necessary actions to protect against this vulnerability.

Why it matters

Defenders should care about CVE-2026-107393 because it allows for stored HTML injection in administrator alert emails via spoofed CF-Connecting-IP headers in FreeScout versions prior to 1.8.235. This could lead to potential security risks if exploited. Defenders responsible for FreeScout instances should verify their version, assess exposure, and update to 1.8.235 or later if necessary.

  • Potential execution of injected HTML in administrator alert emails.
  • Possible spoofing of CF-Connecting-IP header values.
  • Need for verification of FreeScout version and exposure.
  • Potential for HTML injection attacks via LogsMonitor

Technical summary

The vulnerability exists in FreeScout versions prior to 1.8.235. When APP_CLOUDFLARE_IS_USED is enabled, FreeScout stores an unvalidated CF-Connecting-IP header value in the activity log during failed login attempts. LogsMonitor inserts this value into administrator alert emails without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue allows for stored HTML injection in administrator alert emails via spoofed CF-Connecting-IP headers. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially if they are using FreeScout versions prior to 1.8.235.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially if they are using FreeScout versions prior to 1.8.235.

Recommended defensive actions

  • Verify if the FreeScout instance is using a version prior to 1.8.235 and update to 1.8.235 or later if necessary.
  • Assess the exposure of FreeScout instances to untrusted networks or users who could potentially spoof the CF-Connecting-IP header.
  • Review administrator alert emails for any suspicious content that could indicate exploitation.
  • Consider implementing additional security measures to protect against similar vulnerabilities in the future.
  • Confirm whether affected FreeScout deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and source item provide details about the vulnerability, including its existence in FreeScout versions prior to 1.8.235 and the fix in version 1.8.235. However, there is limited information about potential exploitation or specific impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107393 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107393

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107393 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107393

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • FreeScout: Stored HTML Injection in Administrator Alert Emails via Spoofed CF-Connecting-IP Head

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107393.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.