CVE-2026-11596: Medium severity ConnectWise ScreenConnect vulnerability

Published Jun 10, 2026
·
Updated

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

Affected Software

1 affected component
ConnectWise ScreenConnect<26.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ScreenConnect to a version that resolves this vulnerability.

    Fixed in 26.2
  2. Operational

    No action required for ScreenConnect servers hosted in the ScreenConnect cloud environment; those servers have been updated to remediate this issue.

Event History

Jun 10, 2026
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11596?

CVE-2026-11596 has a medium severity rating of 4.7.

2

How do I fix CVE-2026-11596?

To fix CVE-2026-11596, upgrade to ScreenConnect version 26.2 or later if you are using an on-prem server.

3

Who is affected by CVE-2026-11596?

CVE-2026-11596 affects authenticated users with Host Pass creation privileges in ScreenConnect versions prior to 26.2.

4

What type of vulnerability is CVE-2026-11596?

CVE-2026-11596 is an input validation vulnerability related to the Host Pass creation functionality.

5

Is there a need for action if using the cloud version of ScreenConnect regarding CVE-2026-11596?

No action is required for cloud-hosted ScreenConnect servers as they have been updated to remediate CVE-2026-11596.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203