CVE-2026-84869
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ConnectWise | ScreenConnect | All versions prior to 26.6.5 | affected |
Weaknesses
- CWE-862: CWE-862 Missing Authorization
- CWE-269: CWE-269 Improper Privilege Management
Workarounds
If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you can implement the following as a temporary mitigation to help reduce exposure until the update can be applied. This is not a substitute for installing the security update.
- Navigate to the Administration > Security > Roles section.
- Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected.
- Save your changes. Repeat for each role.
References
- https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
- https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869
- https://www.connectwise.com/company/trust/advisories
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.