CVE-2023-23126: ConnectWise Automate
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
Affected products
- ConnectWise Automate: version 2022.11 only
Published 2023-02-01. Last modified 2026-06-17.