CVE-2026-11596
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.7 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Vulnerability Description
In ScreenConnect™ versions prior to 26.2, input
validation within the Host Pass creation functionality could allow an
authenticated user with Host Pass creation privileges the ability to specify a
token expiration duration beyond the intended maximum when generating delegated
access tokens.
validation within the Host Pass creation functionality could allow an
authenticated user with Host Pass creation privileges the ability to specify a
token expiration duration beyond the intended maximum when generating delegated
access tokens.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-1284
Source
NVD
Vendor
ConnectWise
Product
ScreenConnect
Discussion (0)
Add Comment
No comments yet. Be the first!