CVE-2026-11596: ConnectWise ScreenConnect

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

Affected products

  • ConnectWise ScreenConnect: before 26.2.2.9585 (fixed in 26.2.2.9585)

Published 2026-06-10. Last modified 2026-08-18.