CVE-2026-53595 is an improper-authentication vulnerability in FreeScout before 1.8.224. A publicly accessible user-setup workflow locates an account using only an invitation hash, then replaces that account's email address and password and establishes an authenticated session. Activated accounts have an empty invitation hash; under MySQL or MariaDB trailing-space comparison semantics permit attacker-controlled whitespace to match that empty value and select the lowest-ID activated account. The invitation-expiry validation can also be bypassed because failed decryption returns the original input, allowing a plaintext numeric timestamp to satisfy the time-to-live check.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit containing one Bash script (exploit.sh) and a README. It is not part of a larger exploitation framework. The script operationalizes a two-stage exploit chain against FreeScout <= 1.8.223: first, it abuses CVE-2026-53595 to perform anonymous account takeover by requesting and posting to /user-setup/%20/<current_unix_timestamp>, extracting a CSRF token from the setup form, and overwriting the targeted account's email and password. The logic relies on the documented behavior that an activated user's invite_hash is empty, that MySQL/MariaDB VARCHAR comparison ignores trailing spaces so %20 matches '', and that the invite_sent_at validation accepts a plaintext timestamp when decryption fails. After takeover, the script uses the authenticated upload endpoint /uploads/upload to exploit CVE-2026-53593 by uploading a temporary .pht file containing a minimal PHP webshell (system($_GET["c"])). It parses the JSON response with jq to recover the uploaded file URL, then either executes a single attacker-supplied command through the webshell or sends a base64-encoded Bash reverse shell one-liner to avoid quoting and /bin/sh compatibility issues. The expected result is command execution as the web server user, typically www-data. Repository structure is minimal and purpose-built: README.md documents the vulnerability chain, affected versions, usage examples, requirements, and remediation; exploit.sh contains all exploit logic, argument parsing, CSRF extraction, takeover requests, upload handling, and payload delivery. This is a real exploit rather than a detector, with hardcoded but user-adjustable credentials and callback parameters, making it an operational PoC rather than a framework-grade weaponized module.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only identifies CVE-2026-53595 in the context of adding a template; it provides no technical details about the vulnerability, affected software, impact, or remediation.
An authentication bypass/account takeover vulnerability in FreeScout that allows an unauthenticated attacker to take over the lowest-id activated account by abusing an empty invite_hash match and bypassing the invite expiry check.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.