Input Validation Flaw in ScreenConnect Product by ConnectWise
CVE-2026-11596
4.7MEDIUM
What is CVE-2026-11596?
An input validation issue exists within the Host Pass creation functionality of ScreenConnect, allowing authenticated users who possess Host Pass creation privileges to set a token expiration duration beyond the allowable limit. This can lead to unintended access permissions, raising concerns about token management and security controls.
Affected Version(s)
ScreenConnect All versions prior to 26.2