Medium severity4.7NVD Advisory· Published Jun 10, 2026· Updated Aug 18, 2026
CVE-2026-11596
CVE-2026-11596
Description
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:connectwise:screenconnect:*:*:*:*:*:*:*:*range: <26.2.2.9585
- (no CPE)range: <26.2
Patches
Vulnerability mechanics
References
1- github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-11596nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.