216.73.216.36

CVE-2026-11596

· Published 10/06/2026 18:16 · Modified 10/06/2026 20:19

Labels: CVE-2026-11596 2026-06-107d616e1a-3288-43b1-a0dd-0a65d3e70a49CVE-2026-11596CWE-1284

Essential information

Published
10/06/2026 18:16
Modified
10/06/2026 20:19
Author
Creator
CVSS
4.7 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
NVD
View on NVD

Affected products (CPE)

ProductCPE
screenconnect / screenconnect cpe:2.3:a:screenconnect:screenconnect:<26.2:*:*:*:*:*:*:*

References