CVE-2026-11596: Medium severity ConnectWise ScreenConnect vulnerability
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ScreenConnectto a version that resolves this vulnerability.Fixed in 26.2 - Operational
No action required for ScreenConnect servers hosted in the ScreenConnect cloud environment; those servers have been updated to remediate this issue.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11596?
CVE-2026-11596 has a medium severity rating of 4.7.
How do I fix CVE-2026-11596?
To fix CVE-2026-11596, upgrade to ScreenConnect version 26.2 or later if you are using an on-prem server.
Who is affected by CVE-2026-11596?
CVE-2026-11596 affects authenticated users with Host Pass creation privileges in ScreenConnect versions prior to 26.2.
What type of vulnerability is CVE-2026-11596?
CVE-2026-11596 is an input validation vulnerability related to the Host Pass creation functionality.
Is there a need for action if using the cloud version of ScreenConnect regarding CVE-2026-11596?
No action is required for cloud-hosted ScreenConnect servers as they have been updated to remediate CVE-2026-11596.