Executive brief
ConnectWise ScreenConnect is a remote support and access platform used by IT professionals to manage devices. A vulnerability in the 'Host Pass' feature allows authorized users to create access tokens that last longer than the company's security policies should allow. This could result in persistent, unauthorized access to remote systems if a temporary access token does not expire when expected.
Technical details
An improper validation of specified quantity (CWE-1284) exists in the Host Pass creation functionality of ConnectWise ScreenConnect. Authenticated users with Host Pass creation privileges can bypass server-side validation to specify a token expiration duration that exceeds the intended maximum limit. This allows for the generation of delegated access tokens with an extended lifetime, potentially granting prolonged access to remote hosts beyond administrative intent. The vulnerability is reachable over the network but requires high privileges (PR:H) to exploit. The issue is resolved in version 26.2.
Affected products
- ConnectWise ScreenConnect prior to 26.2
Timeline
- 2026-04-29: patched: Version 26.2 released to address the issue.
- 2026-06-10: disclosed: Public advisory and CVE assignment.