CVE-2020-15838: ConnectWise Automate
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
Affected products
- ConnectWise Automate: before 2020.8 (fixed in 2020.8)
Published 2020-10-09. Last modified 2026-06-17.