THREAT OPS › CVEs › CVE-2026-84869
CVE-2026-84869 — ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
Vulnerability details
- Affected productsScreenConnect
- KEV remediation due2026-09-14
Related reporting
- [NVD] CVE-2026-84869 (CRITICAL 9.9) — A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.nvd
- CISA Adds Three Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-84869 — ConnectWise ScreenConnect: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerabilitycisa_kev
- ConnectWise security advisory (AV26-903)cccs_ca