CVE-2026-11596
CVE-2026-11596 is a medium-severity vulnerability in Connectwise Screenconnect with a CVSS 3.x base score of 4.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1284.
Key facts
- Severity: Medium (CVSS 3.x base score 4.7)
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-36079
- Weakness: CWE-1284
- Affected product: Connectwise Screenconnect
- Published:
- Last modified:
Description
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
Frequently asked questions
- What is CVE-2026-11596?
- In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
- How severe is CVE-2026-11596?
- CVE-2026-11596 has a CVSS 3.x base score of 4.7, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-11596 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-11596?
- CVE-2026-11596 affects Connectwise Screenconnect. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-11596?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-11596 have an EU (EUVD) identifier?
- Yes. CVE-2026-11596 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-36079.
- When was CVE-2026-11596 published?
- CVE-2026-11596 was published on 2026-06-10 and last updated on 2026-08-18.
References
Affected products (1)
- cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*
More vulnerabilities in Connectwise Screenconnect
- CVE-2024-1709 — Critical (CVSS 10.0): ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or…
- CVE-2026-84869 — Critical (CVSS 9.9): A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session…
- CVE-2025-14265 — Critical (CVSS 9.1): In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension…
- CVE-2024-1708 — High (CVSS 8.4): ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker…
- CVE-2025-3935 — High (CVSS 8.1): ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web…
- CVE-2023-47257 — High (CVSS 8.1): ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via…
All CVEs affecting Connectwise Screenconnect →
Other CWE-1284 (Improper Validation of Specified Quantity in Input) vulnerabilities
- CVE-2026-81779 — Critical (CVSS 10.0): Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software…
- CVE-2026-49777 — Critical (CVSS 10.0): Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for…
- CVE-2024-8887 — Critical (CVSS 10.0): CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with…
- CVE-2022-20699 — Critical (CVSS 10.0): Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker…
- CVE-2021-21960 — Critical (CVSS 10.0): A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect…
- CVE-2021-21951 — Critical (CVSS 10.0): An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the…
Browse all CWE-1284 (Improper Validation of Specified Quantity in Input) vulnerabilities →