CVE-2026-28289
FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution
Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.
In plain language
AI Worth attentionFreeScout versions up to 1.8.206 have a file-upload bypass that can let an attacker run code on your server; if you use FreeScout and allow uploads, you should update to 1.8.207 now.
In FreeScout (CVE-2026-28289), a patch bypass in the uploaded file name handling (CWE-434) allows an authenticated user with file upload permissions to upload a specially crafted .htaccess name (using a zero-width space character) to achieve Remote Code Execution.
What to do now
- Check your FreeScout version in the application (Help/About or Admin settings) and confirm whether you are running 1.8.206 or earlier.
- If you are on 1.8.206 or earlier, plan an immediate update to FreeScout 1.8.207.
- After updating, verify you can no longer reproduce the upload behavior using your normal upload features (and ensure upload permissions remain limited to trusted staff).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-28289 and every CVE in our database. Create a free account — no credit card required.
Create Free Account