CVE-2026-84869

ConnectWise ScreenConnect: Schwachstelle ermöglicht Codeausführung

criticalEPSS 0.4 %

Beschreibung

Eine Bedingung im ScreenConnect-Client kann es unter bestimmten Umständen ermöglichen, Dateien über eine aktive Remote-Sitzung zu übertragen und auszuführen, ohne Autorisierung oder Bestätigung des Hosts. Die ScreenConnect-Server sind nicht betroffen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.9
Quelle: cna-v3
31.6 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-10 05:46 UTC
CWE-269, CWE-862

Weakness-Klassen (CWE)

  • CWE-269Class

    Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

    cwe.mitre.org →
  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-11 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-84869","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-84869","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-09-09 21:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-84869","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-08 20:18 UTC· 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
    • Description: A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-269
    • CWE: CWE-862

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • ConnectWise

    ScreenConnect< 26.6.5

    gefixt in 26.6.5

IDCVE-2026-84869