Impact
The updated CVE description indicates that a fault in the ScreenConnect server component may enable an attacker with access to server‑level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in specific situations. Host and guest client agents are not independently impacted by this vulnerability.
Affected Systems
The vulnerability affects ConnectWise ScreenConnect installations, including cloud-hosted services (screenconnect.com and hostedrmm.com) and all on‑premise deployments. Vendor guidance confirms that any on‑premise instance running a version older than 26.1 is vulnerable, and integrations with Automate must also be updated to 26.1 through the Automate Product Updates portal.
Risk and Exploitability
The CVSS score of 9 denotes critical severity, while the EPSS score of <1% indicates a very low likelihood of exploitation. The flaw is located within the Server component of ScreenConnect. An attacker who obtains or has privileged access to the server‑level cryptographic material used for authentication can exploit this vulnerability to gain unauthorized access, including elevated privileges. The vulnerability is not listed in the CISA KEV catalog. Existing mitigations for cloud-hosted deployments are already in place. On‑premise users must apply the 26.1 update to remediate the issue; controlling access to server‑level cryptographic material and monitoring logs remain best practices for environments where patching cannot be performed immediately.
OpenCVE Enrichment