High severity8.8NVD Advisory· Published Oct 9, 2020· Updated Jun 17, 2026
CVE-2020-15838
CVE-2020-15838
Description
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:*range: <2020.8
- (no CPE)range: <2020.8
- ConnectWise/Automatedescription
Patches
Vulnerability mechanics
References
2- dbeta.com/2020/10/05/PrivilegeEscalationInAutomateAgentnvdThird Party Advisory
- www.connectwise.com/company/trust/security-bulletinsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.