CVE-2026-6066 Details
Description
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate deployments. The issue has been resolved in Automate 2026.4 by enforcing secure communication for affected Solution Center connections.
A vulnerability exists in ConnectWise Automate prior to version 2026.4, where certain client-to-server communications in the Solution Center could occur without transport-layer encryption. This lack of encryption could enable network-based interception of Solution Center traffic in affected Automate deployments. The issue has been addressed in version 2026.4 by enforcing secure communication for the impacted Solution Center connections.
ConnectWise Automate users should update to version 2026.4. After applying the update, on-premises customers must ensure an SSL certificate is bound to the Solution Center on port 8484 to establish secure communication. Consult the ConnectWise documentation for guidance on this configuration. Additionally, verify that the LTShare has at least 1 GB of free disk space before installation. If issues arise during the update process, ConnectWise Support can provide assistance.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.connectwise.com/company/trust/security-bulletins/2026-04-20-connectwise-automate-bulletin | ConnectWise | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | ConnectWise |
Affected Products
| Product | Versions |
|---|---|
| connectwise automate | < 2026.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ConnectWise |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | New CVE Received | ConnectWise |