Executive brief
ConnectWise ScreenConnect is a remote desktop software used by IT teams to provide technical support and manage computers. A vulnerability in the server component could allow an attacker who has obtained specific server security keys to bypass authentication and gain full control over the system, including elevated administrative privileges. This could lead to unauthorized access to all managed customer machines and sensitive data.
Technical details
A vulnerability exists in the ConnectWise ScreenConnect server component due to improper verification of cryptographic signatures (CWE-347). In versions prior to 26.1, unique machine keys used for authentication were stored within server configuration files in a manner that could allow an attacker with access to this cryptographic material to forge authentication tokens. While the attack complexity is high because it requires prior access to server-level secrets, a successful exploit allows for complete authentication bypass and privilege escalation. ConnectWise has addressed this in version 26.1 by implementing encrypted storage and improved management for these machine keys.
Affected products
- ConnectWise ScreenConnect All server versions prior to 26.1
Timeline
- 2026-03-17: disclosed
- 2026-03-17: patched: Fixed in version 26.1
- 2026-03-17: advisory