CVE-2026-84869
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49 (Secondary)
Description
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Related CWEs
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-862
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
References (3)
Source: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
Source: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
Source: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
Timeline
No history available yet.