CVE-2023-23126: ConnectWise Automate

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

Affected products

Published 2023-02-01. Last modified 2026-06-17.