PT-2026-33785 · Connectwise · Connectwise Automate

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-6066

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ConnectWise Automate versions prior to 2026.4
Description A behavior in the ConnectWise Automate Solution Center allows certain client-to-server communications to occur without transport-layer encryption. This lack of encryption could enable network-based interception of Solution Center traffic in Automate deployments.
Recommendations Update to version 2026.4.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6066

Affected Products

Connectwise Automate