PatchSiren cyber security CVE debrief
CVE-2026-107393 freescout-help-desk CVE debrief
FreeScout, a self-hosted help desk and shared mailbox, had a stored HTML injection vulnerability prior to version 1.8.235. When the APP_CLOUDFLARE_IS_USED setting is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts. The spoofed value is stored in the activity log and, without HTML escaping, is inserted into administrator alert emails by LogsMonitor. This allows injected HTML to execute when an administrator opens the email.
- Vendor
- freescout-help-desk
- Product
- freescout
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for FreeScout instances, especially those using versions prior to 1.8.235, should assess their exposure and take necessary actions to protect against this vulnerability.
Why it matters
Defenders should care about CVE-2026-107393 because it allows for stored HTML injection in administrator alert emails via spoofed CF-Connecting-IP headers in FreeScout versions prior to 1.8.235. This could lead to potential security risks if exploited. Defenders responsible for FreeScout instances should verify their version, assess exposure, and update to 1.8.235 or later if necessary.
- Potential execution of injected HTML in administrator alert emails.
- Possible spoofing of CF-Connecting-IP header values.
- Need for verification of FreeScout version and exposure.
- Potential for HTML injection attacks via LogsMonitor
Technical summary
The vulnerability exists in FreeScout versions prior to 1.8.235. When APP_CLOUDFLARE_IS_USED is enabled, FreeScout stores an unvalidated CF-Connecting-IP header value in the activity log during failed login attempts. LogsMonitor inserts this value into administrator alert emails without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue allows for stored HTML injection in administrator alert emails via spoofed CF-Connecting-IP headers. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially if they are using FreeScout versions prior to 1.8.235.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially if they are using FreeScout versions prior to 1.8.235.
Recommended defensive actions
- Verify if the FreeScout instance is using a version prior to 1.8.235 and update to 1.8.235 or later if necessary.
- Assess the exposure of FreeScout instances to untrusted networks or users who could potentially spoof the CF-Connecting-IP header.
- Review administrator alert emails for any suspicious content that could indicate exploitation.
- Consider implementing additional security measures to protect against similar vulnerabilities in the future.
- Confirm whether affected FreeScout deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and source item provide details about the vulnerability, including its existence in FreeScout versions prior to 1.8.235 and the fix in version 1.8.235. However, there is limited information about potential exploitation or specific impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107393 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107393
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107393 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107393
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
FreeScout: Stored HTML Injection in Administrator Alert Emails via Spoofed CF-Connecting-IP Head
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107393.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.