Vulnerability Description
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Screenconnect | < 26.2.2.9585 |
Related Weaknesses (CWE)
References
- https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-11596PatchVendor Advisory
FAQ
What is CVE-2026-11596?
CVE-2026-11596 is a vulnerability with a CVSS score of 4.7 (MEDIUM). In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a tok...
How severe is CVE-2026-11596?
CVE-2026-11596 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11596?
Check the references section above for vendor advisories and patch information. Affected products include: Connectwise Screenconnect.