# CVE-2026-84869 September 8, 2026 --- ## Description A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. --- ## CVSS 3.1 9.9 (Critical) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H --- ## Common Weakness Enumeration CWE-862: Missing Authorization CWE-269: Improper Privilege Management --- ## Details Earlier versions of ScreenConnect Client Support and Access sessions contained a client-side file-transfer handling condition in which file-transfer actions could be processed through an active remote session without proper authorization or Host confirmation. Under certain circumstances, this could allow files to be transferred to and executed on the Host client system, including through elevated execution actions. ScreenConnect servers are not impacted. Disabling file-transfer permissions for affected sessions may reduce exposure until the update is applied. --- ## Resolution ### Cloud - No action is required. ScreenConnect servers hosted in the ScreenConnect cloud environment have been updated to remediate this issue. - We recommend updating your host clients (https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_client/Reinstall_the_host_client) and access agents (https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_page/Reinstall_and_upgrade_an_access_agent). ### On-Premise - Upgrade to ScreenConnect version 26.6.5 or later. - For Automate-integrated ScreenConnect deployments: Automate partners are eligible to update their integrated on-premises ScreenConnect installation as long as their Automate Assurance subscription is active. Automate partners should apply the ScreenConnect 26.6.5 update through Automate Product Updates. - If your ScreenConnect license is out of maintenance, renew or upgrade the license before installing the latest supported release. - If you are unable to apply the update immediately due to maintenance windows or change-freeze policies, you can implement the following as a temporary mitigation to help reduce exposure until the update can be applied. This is not a substitute for installing the security update. 1. Navigate to the Administration > Security > Roles section. 2. Edit a role, review each session group that has permissions assigned to it, and deselect the TransferFiles permission if it is selected. 3. Save your changes. Repeat for each role. --- ## Affected Products - ScreenConnect versions prior to 26.6.5 --- ## Fixed Version - ScreenConnect 26.6.5 and later --- ## References - https://www.cve.org/cverecord?id=CVE-2026-84869 - https://www.connectwise.com/company/trust/advisories