CVE-2026-3564

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-17 15:16

Updated : 2026-07-09 18:16


NVD link : CVE-2026-3564

Mitre link : CVE-2026-3564

CVE.ORG link : CVE-2026-3564


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature