CVE Details

CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Published: 2026-09-11 CVSS: 9.9 CRITICAL Product: ConnectWise ScreenConnect Due Date: 2026-09-14

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

No GitHub PoC data.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.9
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-84869
cveMetadata > assignerOrgId 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName ConnectWise
cveMetadata > dateReserved 2026-09-02T13:57:51.898Z
cveMetadata > datePublished 2026-09-08T19:29:33.630Z
cveMetadata > dateUpdated 2026-09-11T19:58:23.379Z
containers > cna > providerMetadata > orgId 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
containers > cna > providerMetadata > shortName ConnectWise
containers > cna > providerMetadata > dateUpdated 2026-09-08T19:29:33.630Z
containers > cna > title ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-862
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-862 Missing Authorization
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > problemTypes > 1 > descriptions > 0 > lang en
containers > cna > problemTypes > 1 > descriptions > 0 > cweId CWE-269
containers > cna > problemTypes > 1 > descriptions > 0 > description CWE-269 Improper Privilege Management
containers > cna > problemTypes > 1 > descriptions > 0 > type CWE
containers > cna > impacts > 0 > capecId CAPEC-1
containers > cna > impacts > 0 > descriptions > 0 > lang en
containers > cna > impacts > 0 > descriptions > 0 > value CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
containers > cna > affected > 0 > vendor ConnectWise
containers > cna > affected > 0 > product ScreenConnect
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version All versions prior to 26.6.5
containers > cna > affected > 0 > defaultStatus unaffected
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
containers > cna > descriptions > 0 > supportingMedia > 0 > type text/html
containers > cna > descriptions > 0 > supportingMedia > 0 > base64 False
containers > cna > descriptions > 0 > supportingMedia > 0 > value A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
containers > cna > references > 0 > url https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
containers > cna > references > 1 > url https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
containers > cna > references > 2 > url https://www.connectwise.com/company/trust/advisories
containers > cna > metrics > 0 > format CVSS
containers > cna > metrics > 0 > scenarios > 0 > lang en
containers > cna > metrics > 0 > scenarios > 0 > value GENERAL
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV3_1 > privilegesRequired LOW
containers > cna > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > cna > metrics > 0 > cvssV3_1 > scope CHANGED
containers > cna > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV3_1 > baseScore 9.9
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
containers > cna > workarounds > 0 > lang en
containers > cna > workarounds > 0 > value If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you can implement the following as a temporary mitigation to help reduce exposure until the update can be applied. This is not a substitute for installing the security update. * Navigate to the Administration > Security > Roles section. * Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected. * Save your changes. Repeat for each role.
containers > cna > workarounds > 0 > supportingMedia > 0 > type text/html
containers > cna > workarounds > 0 > supportingMedia > 0 > base64 False
containers > cna > workarounds > 0 > supportingMedia > 0 > value <p>If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you can implement the following as a temporary mitigation to help reduce exposure until the update can be applied. <b>This is not a substitute for installing the security update</b>.</p> <p></p><ol><li>Navigate to the <b>Administration &gt; Security &gt; Roles</b> section. </li><li>Edit a role, review each session group that has permissions assigned to it, and deselect the <b>TransferFiles</b> permission if it is selected.</li><li>Save your changes. Repeat for each role.</li></ol><p></p>
containers > cna > solutions > 0 > lang en
containers > cna > solutions > 0 > value Cloud: Updated to the latest release. We recommend that partners reinstall their host clients https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_client/Reinstall_the_host_client and update their access agents https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_page/Reinstall_and_upgrade_an_access_agent . On-prem: Upgrade to ScreenConnect client version 26.6.5 or later. Automate-integrated ScreenConnect deployments: Automate partners are eligible to update their integrated on-premises ScreenConnect installation as long as their Automate Assurance subscription is active. Automate partners should apply the ScreenConnect 26.6.5 update through Automate Product Updates.
containers > cna > solutions > 0 > supportingMedia > 0 > type text/html
containers > cna > solutions > 0 > supportingMedia > 0 > base64 False
containers > cna > solutions > 0 > supportingMedia > 0 > value <p><b>Cloud:&nbsp;</b><span>Updated to the latest release. We recommend that partners </span><a href="https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_client/Reinstall_the_host_client">reinstall their host clients</a><span> and </span><a href="https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_page/Reinstall_and_upgrade_an_access_agent">update their access agents</a><span>.</span></p><p><b>On-prem</b>:&nbsp;<span>Upgrade to ScreenConnect client version </span><span>26.6.5 </span><span>or later.</span></p><p><b>Automate-integrated ScreenConnect deployments:&nbsp;</b><span>Automate partners are eligible to update their integrated on-premises ScreenConnect installation as long as their Automate Assurance subscription is active. Automate partners should apply the ScreenConnect </span><span>26.6.5 </span><span>update through Automate Product Updates.</span></p>
containers > cna > source > discovery UNKNOWN
containers > cna > x_generator > engine Vulnogram 1.0.5
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > id CVE-2026-84869
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable no
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > metrics > 0 > other > content > timestamp 2026-09-11T18:50:39.725092Z
containers > adp > 0 > metrics > 1 > other > type kev
containers > adp > 0 > metrics > 1 > other > content > dateAdded 2026-09-11
containers > adp > 0 > metrics > 1 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
containers > adp > 0 > references > 0 > url https://www.huntress.com/blog/rogue-screenconnect-installations
containers > adp > 0 > references > 0 > tags > 0 third-party-advisory
containers > adp > 0 > references > 1 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869
containers > adp > 0 > references > 1 > tags > 0 government-resource
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-09-11T19:58:23.379Z
containers > adp > 0 > timeline > 0 > time 2026-09-11T00:00:00.000Z
containers > adp > 0 > timeline > 0 > lang en
containers > adp > 0 > timeline > 0 > value CVE-2026-84869 added to CISA KEV