CVE-2026-84869
9.9ConnectWise · ScreenConnect
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
Executive summary
A critical authorization vulnerability in ConnectWise ScreenConnect allows authenticated attackers to execute arbitrary files on remote systems without host confirmation, posing a severe risk to client integrity.
Vulnerability
This vulnerability involves missing authorization (CWE-862) and improper privilege management (CWE-269), which permits a low-privileged authenticated user to bypass confirmation prompts for file operations. The flaw effectively allows an attacker to achieve remote code execution on the endpoint during an active session.
Business impact
The exploitation of this vulnerability results in full system compromise, as it grants attackers the ability to execute unauthorized code on client endpoints. With a CVSS score of 9.9, the impact is classified as critical, potentially leading to widespread malware deployment, data theft, or complete loss of control over managed assets. Such incidents could result in significant operational disruption and severe reputational damage to organizations relying on ScreenConnect for remote management.
Remediation
Immediate Action: Update all ScreenConnect client installations to version 26.6.5 or later, and ensure that host clients and access agents are reinstalled or upgraded immediately.
Proactive Monitoring: Review audit logs for unusual file transfer activity or unauthorized process execution originating from the ScreenConnect client service during active sessions.
Compensating Controls: While a patch is available, organizations can restrict network access to the ScreenConnect service to trusted management subnets to reduce the attack surface for unauthorized users.
Exploitation status
Public Exploit Available: No (exploit_available unknown).
Analyst recommendation
Given the critical nature of this vulnerability and the potential for complete system compromise, organizations must prioritize the deployment of version 26.6.5 across all environments. Security teams should treat this as a high-priority patch cycle, ensuring that both the server and all endpoint agents are updated to prevent potential exploitation of the client-side authorization flaw.
More ConnectWise CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section