CVE-2026-40591 | freescout-help-desk freescout up to 1.8.213 Conversation customer_id/name/to_email/phone authorization (GHSA-9ff4-mmhv-x6jp)
A vulnerability labeled as critical has been found in freescout-help-desk freescout up to 1.8.213. This affects an unknown part of the component Conversation Handler. The manipulation of the argument customer_id/name/to_email/phone results in authorization bypass.
This vulnerability is identified as CVE-2026-40591. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.