CVE-2026-3564 Details
Description
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.
A vulnerability in ConnectWise ScreenConnect prior to version 26.1 allows unauthorized access, including elevated privileges, by exploiting server-level cryptographic material used for authentication. Earlier versions stored unique machine keys in server configuration files, which could be extracted and misused for session authentication. The vulnerability arises in scenarios where server integrity may be compromised.
Users are advised to upgrade to ScreenConnect version 26.1. For on-premises installations, this version is available on the ScreenConnect Download page. Partners using an on-premises ScreenConnect installation integrated with ConnectWise Automate can access the update through the Automate Product Updates page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin | ConnectWise |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | ConnectWise |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | ConnectWise |
| Jun 17, 2026 | CVE Modified | ConnectWise |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | New CVE Received | ConnectWise |