CVE-2026-3564

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.
Configurations

No configuration.

History

09 Jul 2026, 18:16

Type Values Removed Values Added
Summary (en) A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. (en) A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. ScreenConnect host and guest client agents are not independently affected by this CVE.

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Una condición en ScreenConnect podría permitir a un actor con acceso a material criptográfico a nivel de servidor utilizado para la autenticación obtener acceso no autorizado, incluyendo privilegios elevados, en ciertos escenarios.

17 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 15:16

Updated : 2026-07-09 18:16


NVD link : CVE-2026-3564

Mitre link : CVE-2026-3564

CVE.ORG link : CVE-2026-3564


JSON object : View

Products Affected

No product.

CWE
CWE-347

Improper Verification of Cryptographic Signature