CVE-2026-6066
7.1ConnectWise · Automate
ConnectWise Automate versions prior to 2026.4 contain a vulnerability in the Solution Center that allows sensitive client-to-server communications to occur without transport-layer encryption.
Executive summary
A vulnerability in the ConnectWise Automate Solution Center allows for unencrypted communication, potentially exposing sensitive data to network-based interception.
Vulnerability
This vulnerability, classified as CWE-319 (Cleartext transmission of sensitive information), occurs because the Solution Center component fails to enforce transport-layer encryption for certain communications. According to the CVSS vector (PR:L), this requires an authenticated user with low privileges to trigger or influence the affected communication path.
Business impact
The lack of encryption for Solution Center traffic creates a significant risk of information disclosure, as attackers positioned on the network could intercept sensitive data transmitted between clients and the server. Given the CVSS score of 7.1, this is a High severity issue that threatens the confidentiality of administrative management traffic, which could facilitate further unauthorized access or lateral movement within the environment.
Remediation
Immediate Action: For on-premises deployments, update to version 2026.4 immediately and ensure that an SSL certificate is correctly bound to the Solution Center on port 8484. Cloud-hosted instances do not require action as the vendor has addressed the issue server-side.
Proactive Monitoring: Review network traffic logs for any unencrypted connections originating from the Automate server or clients. Monitor authentication logs for suspicious activity occurring around the time of potential interception attempts.
Compensating Controls: Utilize network segmentation to restrict access to the Automate server management ports to trusted internal subnets only. Implement a Web Application Firewall or network-level traffic inspection to identify and block insecure communication patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations running on-premises instances of ConnectWise Automate must prioritize the upgrade to version 2026.4 to ensure that all administrative communications are properly encrypted. Failure to patch this vulnerability leaves management traffic exposed to interception, which could lead to a broader compromise of the IT management infrastructure.