ConnectWise patches critical ScreenConnect authentication failure after five days
ConnectWise patched ScreenConnect flaw CVE-2026-84869 five days after warning files could be transferred and executed via active sessions without authorization.
ConnectWise released ScreenConnect client version 26.6.5 and later to fix CVE-2026-84869, an authentication failure in ConnectWise Remote Access allowing unauthorized file transfer and execution through active remote sessions. The company warned customers on September 3 and advised admins to remove the TransferFiles permission from users with open sessions as an interim mitigation. The advisory does not state that exploitation has been observed.
- Fixed in ScreenConnect client 26.6.5 onwards
- CVE-2026-84869 allows unauthorized file transfer and execution in live sessions
- TransferFiles permission removal served as interim mitigation
- Five-day gap between warning and patch
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84869 | Missing authorization in ScreenConnect client allows unauthorized file execution CVE-2026-84869 is a critical authorization flaw (CWE-862 missing authorization, CWE-269 improper privilege management) in the ScreenConnect client, the endpoint-side agent of ConnectWise's widely used remote access and remote support platform, in which files can be transferred to a machine and executed during an active remote session without the expected authorization or without confirmation by the Host (technician). It is triggered in certain circumstances during an active session, with a network attack vector, low attack complexity, low privileges required, and no user interaction per the CVSS 3.1 vector. An actor who obtains or already holds access to a session context could thereby push and run files on the managed endpoint, potentially achieving code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.9, scope changed). Only endpoints running the ScreenConnect client are affected; ScreenConnect servers are not impacted, and the affected client version ranges are governed by ConnectWise security advisory AV26-903 (not enumerated in the available data). The flaw is not currently known to be exploited: it is not in CISA KEV, no public proof of concept is known, and EPSS assigns a modest 0.4% probability of exploitation within the next 30 days (32nd percentile). Do: Follow ConnectWise security advisory AV26-903 and update ScreenConnect clients to the patched version it specifies, noting that ScreenConnect servers do not require remediation. Until patching is complete, monitor active remote sessions, require Host confirmation for file transfers, and review recent sessions on high-value endpoints for unexpected transferred or executed files; given no known exploitation and the active-session prerequisite, prioritize endpoints routinely accessed remotely. | 9.9 | <1% | KEV |
| massplausibly millions of managed endpoints running the ScreenConnect client agent |
Full article83 words · extracted from csoonline.com · click to collapse
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation.
The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session.
The vulnerability, tracked as CVE-2026-84869, has been patched in the ScreenConnect client version 26.6.5 onwards.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4221263/connectwise-patches-critical-screenconnect-authentication-failure-after-five-days-2.html