In ScreenConnect™ versions prior to 26.2, input
Published Jun 10, 2026
4.7
MEDIUMCVSS 3.1
EPSS 0.24%
Description
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
Affected products
-
- Version All versions prior to 26.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ConnectWise | ScreenConnect | unaffected |
|
- < 26.2.2.9585
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Cloud: No action is required. ScreenConnect servers hosted in the ScreenConnect cloud environment have been updated to remediate this issue.
On-prem: Upgrade to ScreenConnect version 26.2 or later.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36079 Advisory
- https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-11596 PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36079 | Advisory | |
| https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-11596 | PatchVendor Advisory |
Change history (0)
No recorded changes yet.