CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107393

MEDIUMCVSS 6.1NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrato

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107393 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107393

MEDIUMCVSS 6.1NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrato

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]