Input Validation Flaw in ScreenConnect Product by ConnectWise
CVE-2026-11596

4.7MEDIUM

Key Information:

Vendor
CVE Published:
10 June 2026

What is CVE-2026-11596?

An input validation issue exists within the Host Pass creation functionality of ScreenConnect, allowing authenticated users who possess Host Pass creation privileges to set a token expiration duration beyond the allowable limit. This can lead to unintended access permissions, raising concerns about token management and security controls.

Affected Version(s)

ScreenConnect All versions prior to 26.2

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Damian West (Austin Group)
.