CVE-2026-84869

Summary

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

Affected Software

VendorProductVersion RangeStatus
ConnectWiseScreenConnectAll versions prior to 26.6.5affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization
  • CWE-269: CWE-269 Improper Privilege Management

Workarounds

If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you can implement the following as a temporary mitigation to help reduce exposure until the update can be applied. This is not a substitute for installing the security update.

  • Navigate to the Administration > Security > Roles section.
  • Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected.
  • Save your changes. Repeat for each role.

References