Zero-Click Threat: FreeScout Vulnerability Allows Unauthenticated Server Takeover via Email
Mar 4, 2026 // 12:36 - Tristan Wall


A critical zero-click Remote Code Execution (RCE)vulnerability, tracked as CVE-2026-28289, has been identified in the open-source helpdesk platform FreeScout. With a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to gain total control over vulnerable servers.

Vulnerability Overview

The defect is a patch bypass for a previous bug that initially required authentication.

  • Root Cause: A Time-of-Check to Time-of-Use (TOCTOU) issue exists in filename sanitization. The application’s dot-prefix check occurs beforeinvisible characters are removed.
  • The Bypass: Attackers prepend a zero-width space character to a filename. This bypasses validation checks intended to block restricted files like .htaccess. Once saved, the character is stripped, leaving a functional malicious file on the server.

Attack Vector and Impact

This exploit is zero-click and requires no authentication.

  • Method: An attacker sends a malicious email to a FreeScout-configured mailbox. The payload is written to disk, allowing the attacker to predict its location and execute commands remotely.
  • Scope: Exploitation leads to full system takeover, permitting exfiltration of sensitive tickets and potential lateral movement.
  • Environment: Installations running on Apachewith AllowOverride All are at the highest risk.

Remediation

The flaw was addressed in the following update:

  • Patch: Upgrade to FreeScout version 1.8.207 or later immediately.
  • Hardening: Review server configurations and restrict AllowOverride settings on Apache.

You can track further updates on the FreeScout Security Vulnerabilities Log or via SecurityWeek’s analysis.

#allows  #email  #news  #server  #takeover  #threat: freescout  #unauthenticated  #via  #vulnerability  #zero-click   —   News