---
id: CVE-2026-107393
title: FreeScout is a self-hosted help desk and shared mailbox
summary: >-
  FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235,
  when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated
  CF-Connecting-IP header during failed login attempts and stores the spoofed
  value in the a…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
  - CWE-116
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:33:42.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107393'
references:
  - url: >-
      https://github.com/freescout-help-desk/freescout/commit/0f41f5cabb581de156ec8eb344ff6c0e6e0cc66a
    label: security-advisories@github.com
  - url: 'https://github.com/freescout-help-desk/freescout/releases/tag/1.8.235'
    label: security-advisories@github.com
  - url: >-
      https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9cm3-qvj2-8hg4
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-08T21:07:56.433Z'
---

## Overview

FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
