ScreenConnect CVE-2026-84869: file execution without host approval
A ScreenConnect client flaw can transfer and execute a file in an active session without host authorisation. CVSS 9.9, CISA KEV and the 26.6.5 fix make this urgent.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 12 September 2026
- READING TIME
- 11 min read
- TOPIC
- Vulnerabilities and CVEs
ConnectWise has released ScreenConnect 26.6.5 with a fix for CVE-2026-84869. Under certain conditions, the remote-access client vulnerability may allow a file to be transferred and executed during an active session without the required authorisation or confirmation from the person at the host computer.
The flaw has a CVSS 9.9 score. CISA placed it in the Known Exploited Vulnerabilities catalogue on 11 September and identified a need for forensic triage. For an organisation using a product that inherently reaches client desktops and systems, that combination calls for urgent patching and a review of what happened in sessions before the fix.
The client is affected, not the server
ConnectWise’s bulletin explicitly locates this issue in the ScreenConnect client and says servers are not affected by this particular vulnerability. It is easy to turn that distinction into the wrong conclusion: “the server is current, so the work is finished.”
The complete picture includes:
- the ScreenConnect instance version;
- host clients used during support sessions;
- persistent access agents on managed devices;
- roles carrying file-transfer permission;
- active and recent sessions.
Updating the server side is the starting point for delivering corrected clients and agents. ConnectWise recommends reinstalling host clients and updating access agents after the upgrade.
What condition an attacker must meet
The CVSS vector contains PR:L, meaning low privileges are required. The vendor description also refers to an active remote session. This is not an unauthenticated attack against every computer carrying a ScreenConnect agent.
That constraint offers limited comfort in an MSP or large helpdesk. A low-privileged technician account, hijacked session or poorly confined role may touch many hosts. Host-side confirmation is an important trust boundary. The CVE can bypass that boundary in the described circumstances.
The vendor is withholding full technical details because of the sensitive nature of the vulnerability. We should not invent a public exploit mechanism or assume every file-execution feature is defective.
Which versions require an update
ScreenConnect releases before 26.6.5 are affected. The primary response for on-premises deployments is to move to 26.6.5 or a newer supported release.
Cloud environments have been updated automatically. Administrators should still confirm the instance version in Administration → Overview, update access agents and ensure host clients are reinstalled as ConnectWise directs.
For on-premises environments, the vendor says the upgrade path to 26.6.5 starts from at least version 25.4. If licensing or an older branch prevents a direct update, the service owner should contact the vendor immediately and apply the risk reduction below in the meantime.
Temporary mitigation: remove TransferFiles
When a change window or freeze policy blocks immediate patching, ConnectWise advises reviewing roles under Administration → Security → Roles. Remove the TransferFiles permission — called TransferFilesInSession in older versions — from every role and assigned session group.
Do this for every role, not only the default. Organisations commonly maintain separate roles for partners, first-line support, administrators and suppliers. One overlooked role preserves the capability the mitigation was meant to remove.
The vendor stresses that mitigation is not a substitute for the security update. After patching, restore only permissions that users genuinely need.
Why CISA KEV raises the priority
CISA added CVE-2026-84869 to KEV on 11 September, signifying evidence of exploitation in the wild. US federal civilian agencies received a 14 September action date under BOD 26-04, and the entry calls for forensic triage.
That deadline does not automatically bind Polish organisations. KEV presence is still a practical risk signal: patch priority no longer rests only on a theoretical CVSS score. Remote-access software sits on a privileged path, so even a modest number of installations may represent broad reach into endpoints.
CISA lists ransomware-campaign use as unknown. “Unknown” neither confirms nor rules out such use.
An update plan that preserves visibility
- Identify every cloud and on-premises instance, including RMM integrations.
- Confirm the version and licence, then update on-premises deployments to 26.6.5 or later.
- Update access agents and reinstall host clients as documented.
- Until the change is complete, remove
TransferFilesfrom every role that does not need it. - Preserve session, audit and authentication logs, plus endpoint telemetry, from the exposure period.
- After patching, review accounts, roles, MFA and recognised administrative devices.
Do not mass-uninstall agents without an impact assessment and recovery plan. Abruptly losing the support channel may make incident response harder. Permission reduction, a controlled update and monitoring provide better continuity.
What to examine during triage
ConnectWise tells organisations that suspect compromise to isolate affected servers, preserve data for analysis and follow the full incident-response process. Here, investigation should connect three perspectives: the technician account, the ScreenConnect session and the endpoint.
Look for sessions at unusual times, connections to unexpected device groups, file transfers without a corresponding ticket and processes launched shortly after a transfer. Compare the file name, hash, path, parent process and subsequent actions. Do not base the decision solely on a file name, which is easy to change.
When a suspicious session used a technician account, revoke its sessions, reset credentials and verify MFA. Review other devices available to the same role. The real incident scope comes from accessible session groups, not the user’s job title.
These are Breachroad recommendations based on the remote-access trust model. They are not official indicators of compromise for the CVE.
Source facts and Breachroad conclusions
The behaviour, CVSS 9.9, affected releases, lack of server impact, version 26.6.5, mitigation and upgrade guidance come from ConnectWise’s CVE-2026-84869 bulletin. Confirmation of exploitation, the addition date, BOD 26-04 action date and triage requirement come from the CISA KEV catalogue.
Breachroad concludes that organisations should investigate the account, session and endpoint as one chain and prioritise rotation from the role’s actual reach. Public sources do not disclose the complete exploit mechanism or a comprehensive IOC set.
If remote access first appeared in a scam call, our guide to AnyDesk and remote-support scams is also useful. We rehearse secure helpdesk procedures and employee response through cybersecurity training, while an IT security audit can examine the wider environment.


