CVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Other sources
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ScreenConnect clientto a version that resolves this vulnerability.Fixed in 26.6.5 - Upgrade
Upgrade
Automate-integrated ScreenConnectto a version that resolves this vulnerability.Fixed in 26.6.5 - Compensating control
If BOD 26-04-compliant mitigations for your environment are unavailable, discontinue use of the ScreenConnect product.
- Operational
Automate-integrated ScreenConnect deployments: update their Cloud deployment to the latest release.
- Operational
Reinstall ScreenConnect host clients for Automate Assurance partners with an active subscription (per vendor reinstall instructions).
- Operational
Update/reinstall ScreenConnect access agents for Automate Assurance partners with an active subscription (per vendor reinstall/upgrade instructions).
Event History
Frequently Asked Questions
Are ScreenConnect servers affected?
No. The issue affects the ScreenConnect client; ScreenConnect servers are not impacted.
What access does an attacker need to exploit this issue?
An attacker needs access as a guest in an active remote session. The vulnerability involves file-transfer actions that can transfer and execute files on the host without authorization or host confirmation in certain circumstances.
Does exploitation require the host user to approve the file or interact with a prompt?
No host confirmation is required in the affected circumstances described. The attack vector is network-based and does not require user interaction.