FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing user account, allowing unauthenticated attackers to enumerate valid helpdesk agent email addresses. This vulnerability is fixed in 1.8.219.
CVE-2026-45294
This medium-severity CVE scores 5.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.2%, top 89% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 5.3
- EG Score
- 5.3(medium)
- EG Risk
- —
- EPSS
- 11.4%
- KEV
- Not listed
Published
May 29, 2026
Last Modified
July 22, 2026
Advisory Details (1)
Auto-updated Jun 15, 2026User Account Enumeration via Password Reset Response Differentiation · Advisory · freescout-help-desk/freescout · GitHub
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-jvmv-2qcp-7855Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Frequently asked(5)
What is CVE-2026-45294?
When was CVE-2026-45294 disclosed?
Is CVE-2026-45294 actively exploited?
What is the CVSS score of CVE-2026-45294?
How do I remediate CVE-2026-45294?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-45294
Is Your Infrastructure Affected by CVE-2026-45294?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.