CVE-2026-53595

CRITICAL

FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-53595. PoCs published by 0xdak.

AI-analyzed exploit summary Exploits a chain of two vulnerabilities in FreeScout ≤1.8.223: CVE-2026-53595 (anonymous account takeover via MySQL VARCHAR trailing-space collision and flawed invite timestamp validation) and CVE-2026-53593 (authenticated .pht file upload bypass) to achieve unauthenticated RCE as www-data.

Description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_hash` column, then overwrites that account's email and password and logs in as it. No authentication, cookie, or prior session is required. After a user activates, FreeScout sets `invite_hash` to the empty string. On MySQL and MariaDB, `VARCHAR` equality ignores trailing spaces, so a single URL-encoded space (`%20`) matches the stored empty string and selects the lowest-id activated user. The expiry guard decrypts `invite_sent_at` with the target's password hash, but `Helper::decrypt` returns its raw input unchanged when decryption fails. A plaintext numeric value such as `9999999999` therefore passes the time-to-live check without any secret. The result is that an anonymous attacker sets the email and password of the lowest-id activated FreeScout account (a support agent, or an administrator if one was added by invitation) and authenticates as that account. Version 1.8.224 contains a fix.

Exploits (1)

github WORKING POC
by 0xdak · shellpoc
https://github.com/0xdak/CVE-2026-53595_exploit

Exploits a chain of two vulnerabilities in FreeScout ≤1.8.223: CVE-2026-53595 (anonymous account takeover via MySQL VARCHAR trailing-space collision and flawed invite timestamp validation) and CVE-2026-53593 (authenticated .pht file upload bypass) to achieve unauthenticated RCE as www-data.

Classification
Working Poc 99%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FreeScout ≤1.8.223 (Laravel-based help desk)
No auth needed
Prerequisites: Target must be running FreeScout ≤1.8.223 · Target must use MySQL/MariaDB with default VARCHAR comparison behavior · Apache mod_php must execute .pht files as PHP · Attacker must have network access to the target
mistral-large-3 · analyzed Jul 22, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 9.4
EPSS 0.0037
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-178 CWE-287 CWE-640
Status published
Products (1)
freescout-help-desk/freescout < 1.8.224
Published Jul 20, 2026
Tracked Since Jul 21, 2026