Impact
A flaw in the ScreenConnect client permits files that are transferred through an active remote session to be executed without any host confirmation or authorization. The vulnerability enables an attacker to run arbitrary code on the client machine, compromising confidentiality, integrity, and availability of the affected system. The weakness is related to improper authorization checks, as indicated by the CWE identifiers for broken access control.
Affected Systems
The issue affects ConnectWise ScreenConnect client installations. Clients running versions prior to 26.6.5 on on‑premises deployments are vulnerable, as are host clients that have not been updated or reinstalled per the vendor’s guidance. Server components of ScreenConnect are not impacted.
Risk and Exploitability
The CVSS score of 9.9 classifies this vulnerability as critical. Although the EPSS score is low, the ease of exploitation in an active remote session environment suggests that it could be abused if an attacker gains access to an active remote support session. The vulnerability is listed in the CISA KEV catalog, indicating a current threat of exploitation.
OpenCVE Enrichment