CVE-2026-28289

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

History

11 Mar 2026, 19:29

Type Values Removed Values Added
Summary
  • (es) FreeScout es una mesa de ayuda gratuita y una bandeja de entrada compartida construida con el framework Laravel de PHP. Una vulnerabilidad de omisión de parche para CVE-2026-27636 en FreeScout 1.8.206 y anteriores permite a cualquier usuario autenticado con permisos de carga de archivos lograr Ejecución Remota de Código (RCE) en el servidor mediante la carga de un archivo .htaccess malicioso utilizando un prefijo de carácter de espacio de ancho cero para omitir la verificación de seguridad. La vulnerabilidad existe en la función sanitizeUploadedFileName() en app/Http/Helper.php. La función contiene una falla de Tiempo de Verificación a Tiempo de Uso (TOCTOU) donde la verificación del prefijo de punto ocurre antes de que la sanitización elimine los caracteres invisibles. Esta vulnerabilidad está corregida en 1.8.207.
References () https://www.ox.security/blog/freescout-rce-cve-2026-28289/ - () https://www.ox.security/blog/freescout-rce-cve-2026-28289/ - Exploit, Vendor Advisory

05 Mar 2026, 22:16

Type Values Removed Values Added
References
  • () https://www.ox.security/blog/freescout-rce-cve-2026-28289/ -

05 Mar 2026, 16:08

Type Values Removed Values Added
References () https://github.com/freescout-help-desk/freescout/commit/f7bc16c56a6b13c06da52ad51fd666546b40818f - () https://github.com/freescout-help-desk/freescout/commit/f7bc16c56a6b13c06da52ad51fd666546b40818f - Patch
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-5gpc-65p8-ffwp - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-5gpc-65p8-ffwp - Exploit, Mitigation, Vendor Advisory
CPE cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*
First Time Freescout
Freescout freescout

03 Mar 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-03 23:15

Updated : 2026-03-11 19:29


NVD link : CVE-2026-28289

Mitre link : CVE-2026-28289

CVE.ORG link : CVE-2026-28289


JSON object : View

Products Affected

freescout

  • freescout
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type