CVE-2023-23128: ConnectWise

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.

Affected products

Published 2023-02-01. Last modified 2026-06-17.