PT-2026-33785 · Connectwise · Connectwise Automate
Published
2026-04-20
·
Updated
2026-04-21
·
CVE-2026-6066
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ConnectWise Automate versions prior to 2026.4
Description
A behavior in the ConnectWise Automate Solution Center allows certain client-to-server communications to occur without transport-layer encryption. This lack of encryption could enable network-based interception of Solution Center traffic in Automate deployments.
Recommendations
Update to version 2026.4.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connectwise Automate