Automate
by Connectwise
CVEs (14)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35066 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. | ||
| CVE-2020-15027 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2020 | ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12. | ||
| CVE-2025-11492 | Cri | 0.62 | 9.6 | 0.00 | Oct 16, 2025 | In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used… | ||
| CVE-2026-9089 | Hig | 0.57 | 8.8 | 0.00 | May 21, 2026 | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5. | ||
| CVE-2025-11493 | Hig | 0.57 | 8.8 | 0.00 | Oct 16, 2025 | The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for… | ||
| CVE-2020-15838 | Hig | 0.57 | 8.8 | 0.01 | Oct 9, 2020 | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions. | ||
| CVE-2020-14159 | Hig | 0.57 | 8.8 | 0.02 | Jun 15, 2020 | By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before… | ||
| CVE-2023-47257 | Hig | 0.53 | 8.1 | 0.01 | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. | ||
| CVE-2021-32582 | Hig | 0.49 | 7.5 | 0.01 | Jun 17, 2021 | An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status… | ||
| CVE-2020-15008 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2020 | A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and… | ||
| CVE-2026-6066 | Hig | 0.46 | 7.1 | 0.00 | Apr 20, 2026 | ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based… | ||
| CVE-2023-23126 | Med | 0.40 | 6.1 | 0.00 | Feb 1, 2023 | Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack. | ||
| CVE-2023-23130 | Med | 0.38 | 5.9 | 0.00 | Feb 1, 2023 | Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP… | ||
| CVE-2023-47256 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings |
- risk 0.64cvss 9.8epss 0.01
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
- risk 0.64cvss 9.8epss 0.01
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.
- risk 0.62cvss 9.6epss 0.00
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used…
- risk 0.57cvss 8.8epss 0.00
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.
- risk 0.57cvss 8.8epss 0.00
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for…
- risk 0.57cvss 8.8epss 0.01
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
- risk 0.57cvss 8.8epss 0.02
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before…
- risk 0.53cvss 8.1epss 0.01
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status…
- risk 0.49cvss 7.5epss 0.01
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and…
- risk 0.46cvss 7.1epss 0.00
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based…
- risk 0.40cvss 6.1epss 0.00
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
- risk 0.38cvss 5.9epss 0.00
Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP…
- risk 0.36cvss 5.5epss 0.00
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings