CVE-2026-28289 | freescout-help-desk freescout up to 1.8.206 .htaccess sanitizeUploadedFileName unrestricted upload (GHSA-5gpc-65p8-ffwp)
A vulnerability described as critical has been identified in freescout-help-desk freescout up to 1.8.206. Affected by this vulnerability is the function sanitizeUploadedFileName of the component .htaccess Handler. The manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2026-28289. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.