A vulnerability labeled as critical has been found in FreeScout up to 1.8.223. Affected by this vulnerability is the function OpenController@userSetupSave of the component User Setup. The manipulation of the argument invite_hash/invite_sent_at results in improper authentication.

This vulnerability is cataloged as CVE-2026-53595. The attack may be launched remotely. There is no exploit available.