CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53595

criticalpublic exploitCVSS 9.4covered by 1 sourcefirst seen 2026-07-20
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-53595 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint POST /user-setup/{hash}/{invite_sent_at} (OpenController@userSetupSave) selects the target account solely by its invite_hash column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets invite_hash to the empty string. On MySQL and MariaDB, VARCHAR equality ignores trailing spaces, so a single URL-encoded space (%20) matches the stored empty string and selects the lowest-id activated user. The expiry guard decrypts invite_sent_at with the target's password hash, but Helper::decrypt returns its raw input unchanged when decryption fails. A plaintext numeric value such as 9999999999 therefore passes the time-to-live check without any secret. The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. Version 1.8.224 contains a fix.

⚡ Watch CVE-2026-53595

Get an email if CVE-2026-53595 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2026-53595 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (1)

External references

NVD record for CVE-2026-53595

CVE.org record

Embed the live status

CVE-2026-53595 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53595 status](https://www.csirts.com/badge/CVE-2026-53595)](https://www.csirts.com/cve/CVE-2026-53595)