Executive brief
ConnectWise ScreenConnect is a remote access and support platform used by IT teams to manage and troubleshoot systems. A critical vulnerability in this tool allows attackers to transfer and run files on a connected system without proper authorization checks, potentially giving them full control over supported computers. The vulnerability is being actively exploited by attackers in real-world attacks.
Technical details
The vulnerability stems from improper privilege management and missing authorization checks in ConnectWise ScreenConnect's file transfer and execution functionality. An attacker with access to an active remote session can bypass authorization controls to transfer arbitrary files and execute code on the target system without requiring explicit user confirmation. The weakness resides in the remote session handling mechanism, which fails to validate user permissions before allowing file operations. No special authentication is required beyond establishing an active remote session. An attacker exploiting this vulnerability can achieve arbitrary code execution and full system compromise. The vendor has released patches; affected users should update to patched versions immediately.
Affected products
- ConnectWise ScreenConnect
Timeline
- 2026-09-11: disclosed
- exploited: Being actively exploited in the wild