ConnectWise ScreenConnect Unauthorized Access Vulnerability via Cryptographic Material Extraction

Vulnerability

A vulnerability in ConnectWise ScreenConnect prior to version 26.1 allows unauthorized access, including elevated privileges, by exploiting server-level cryptographic material used for authentication. Earlier versions stored unique machine keys in server configuration files, which could be extracted and misused for session authentication. The vulnerability arises in scenarios where server integrity may be compromised.

Impact

Exploitation of this vulnerability could lead to unauthorized access and elevated privileges within the ScreenConnect application.

Remediation

Users are advised to upgrade to ScreenConnect version 26.1. For on-premises installations, this version is available on the ScreenConnect Download page. Partners using an on-premises ScreenConnect installation integrated with ConnectWise Automate can access the update through the Automate Product Updates page.

Added: Mar 17, 2026, 3:24 PM
Updated: Mar 17, 2026, 3:24 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
3.6
remediation
7.7
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.