Junglewise Threat Intelligence

CVE-2026-9089: ConnectWise Automate Agent code integrity bypass in self-update

CVE-2026-9089 · Severity: high · CVSS 8.8 · Published 2026-05-21

Vendors: ConnectWise.

Executive brief

ConnectWise Automate is a remote monitoring and management platform used by IT teams to manage computers and servers. A security flaw in the Automate Agent allows it to download and run software updates or plugins without properly verifying that the files are authentic and untampered. If exploited, an attacker on the same local network could trick the agent into running malicious code, potentially leading to a full takeover of the managed device and access to sensitive data.

Technical details

A vulnerability classified as CWE-494 (Download of Code Without Integrity Check) exists in the ConnectWise Automate Agent. The agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations, allowing for the execution of unsigned or malicious code. The attack vector is restricted to the adjacent network (AV:A), meaning an attacker must be on the same local network or subnet as the target agent to intercept or spoof the update traffic. Successful exploitation results in high impacts to confidentiality, integrity, and availability. The issue is resolved in ConnectWise Automate version 2026.5, which introduces enhanced integrity verification.

Affected products

  • ConnectWise Automate Agent versions prior to 2026.5

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: patched: Fixed in version 2026.5

References