MEDIUM🇬🇧 English

CVE-2026-11596

CVSS 4.7v3.1pub. 2026-06-10upd. 2026-08-18

W wersjach ScreenConnect™ wcześniejszych niż 26.2, nieprawidłowa walidacja danych wejściowych w funkcji tworzenia Host Pass umożliwiła uwierzytelnionemu użytkownikowi z uprawnieniami do tworzenia Host Pass określenie czasu wygaśnięcia tokena poza zamierzoną maksymalną wartość podczas generowania delegowanych tokenów dostępu.

Pokaż oryginał (EN)

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
  • Connectwise Screenconnect

    APP
    Connectwise
    < 26.2.2.9585
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2024-1709CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Authentication Bypass w ConnectWise ScreenConnect — bezpośredni dostęp do systemów

CVE-2025-14265CRITICAL9.1PL ✓ten sam produkt

ConnectWise ScreenConnect — instalacja niezaufanych rozszerzeń z RCE

CVE-2025-3935HIGH8.1⚠ KEVten sam produkt

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. AS...

CVE-2024-1708HIGH8.4⚠ KEVten sam produkt

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an at...

CVE-2023-47257HIGH8.1ten sam produkt

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...