PT-2026-25901 · Connectwise · Screenconnect
Published
2026-03-17
·
Updated
2026-03-20
·
CVE-2026-3564
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ScreenConnect versions prior to 26.1
Description
A flaw in ScreenConnect could allow an attacker with access to server-level cryptographic material used for authentication to gain unauthorized access, potentially including elevated privileges. This is due to an improper verification of cryptographic signatures, where earlier versions stored unique machine keys per instance within server configuration files. Exploitation requires prior access to the server-level cryptographic material. The vulnerability is considered critical and has a CVSS score of 9.0. The issue could allow attackers to forge authenticated sessions and escalate privileges within a ScreenConnect instance, potentially impacting downstream client environments, especially given ScreenConnect's use by Managed Service Providers. The machine key attack surface is of particular concern, as publicly exposed machine keys have been observed being misused to inject malicious code into servers.
Recommendations
Upgrade to ScreenConnect version 26.1.
Fix
LPE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Screenconnect