CVE-2026-27637

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is static (never expires/rotates), and if an attacker obtains the `APP_KEY` — a well-documented and common exposure vector in Laravel applications — they can compute a valid token for any user, including the administrator, achieving full account takeover without any password. This vulnerability can be exploited on its own or in combination with CVE-2026-27636. Version 1.8.206 fixes both vulnerabilities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:27

Type Values Removed Values Added
Summary
  • (es) FreeScout es un servicio de asistencia técnica gratuito y un buzón compartido creado con el marco Laravel de PHP. Antes de la versión 1.8.206, el middleware 'TokenAuth' de FreeScout utiliza un token de autenticación predecible calculado como 'MD5(user_id + created_at + APP_KEY)'. Este token es estático (nunca expira/rota), y si un atacante obtiene la 'APP_KEY' — un vector de exposición bien documentado y común en aplicaciones Laravel — pueden calcular un token válido para cualquier usuario, incluido el administrador, logrando una toma de control total de la cuenta sin ninguna contraseña. Esta vulnerabilidad puede ser explotada por sí misma o en combinación con CVE-2026-27636. La versión 1.8.206 corrige ambas vulnerabilidades.

26 Feb 2026, 16:08

Type Values Removed Values Added
References () https://github.com/freescout-help-desk/freescout/commit/004a8231f6e413af1d4680930b0e2342fd4283f9 - () https://github.com/freescout-help-desk/freescout/commit/004a8231f6e413af1d4680930b0e2342fd4283f9 - Patch
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6gcm-v8xf-j9v9 - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6gcm-v8xf-j9v9 - Exploit, Vendor Advisory
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc - Not Applicable
First Time Freescout
Freescout freescout
CPE cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

25 Feb 2026, 16:23

Type Values Removed Values Added
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6gcm-v8xf-j9v9 - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-6gcm-v8xf-j9v9 -
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc -

25 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 04:16

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27637

Mitre link : CVE-2026-27637

CVE.ORG link : CVE-2026-27637


JSON object : View

Products Affected

freescout

  • freescout
CWE
CWE-330

Use of Insufficiently Random Values