CVE-2026-11596

MEDIUM CVSS 3.1: 4.7 EPSS 0.24%
Updated Aug 18, 2026
Connectwise
Parameter Value
CVSS 4.7 (MEDIUM)
Affected Versions before 26.2.2.9585
Fixed In 26.2.2.9585
Type CWE-1284
Vendor Connectwise
Public PoC No

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Connectwise Screenconnect
cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*
26.2.2.9585