CVE-2026-45294

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing user account, allowing unauthenticated attackers to enumerate valid helpdesk agent email addresses. This vulnerability is fixed in 1.8.219.
Configurations

No configuration.

History

02 Jun 2026, 03:16

Type Values Removed Values Added
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-jvmv-2qcp-7855 - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-jvmv-2qcp-7855 -

29 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 20:16

Updated : 2026-06-02 03:16


NVD link : CVE-2026-45294

Mitre link : CVE-2026-45294

CVE.ORG link : CVE-2026-45294


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy

CWE-204

Observable Response Discrepancy