ScreenConnect Client Remote Session File Exec without Auth
CVE-2026-84869 Published on September 8, 2026

ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

NVD

Known Exploited Vulnerability

This ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

The following remediation steps are recommended / required by September 14, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab

Vulnerability Analysis

CVE-2026-84869 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Types

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-84869 has been classified to as an AuthZ vulnerability or weakness.

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-84869

Want to know whenever a new CVE is published for Connectwise Screenconnect? stack.watch will email you.

 

Affected Versions

ConnectWise ScreenConnect Version All versions prior to 26.6.5 is affected by CVE-2026-84869