External risk intelligence

ScreenConnect Client Unauthorized File Transfer and Execution.

CVE advisoryKnown Exploit

CVE-2026-84869

The vulnerability exists within the ScreenConnect client during an active remote session. While remote support tools are network-connected, exploitation requires an ongoing, established session where an attacker must already be interacting with the client, making public internet-facing exploitation uncommon and distinct from typical public-facing web services or gateways.

Connectwise Screenconnect

before 26.6.5.9742

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the ScreenConnect client could allow unauthorized file transfers and execution during active remote sessions. While ScreenConnect servers are unaffected, this condition impacts the client software, potentially enabling malicious actions without host confirmation. The primary concern for leadership is to confirm whether this specific client software is in use and if it is exposed to such scenarios.

  • Unauthorized file transfers and execution are possible.
  • Client software could be compromised during active sessions.
  • Confirm relevance and exposure of the client software.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to an active ScreenConnect remote session could potentially transfer and execute files on the client machine without needing further authorization. This bypasses the usual security checks that require host confirmation for such actions, and if successful, could lead to significant compromise.

  • Requires authenticated active session.
  • Unauthorized file transfer and execution.
  • Leads to client compromise.

Live Threat

Current exploitation, exposure, and threat context

Under supported conditions, an unauthenticated or unauthorized user could transfer and execute arbitrary files through an active ScreenConnect remote session, potentially impacting the security and integrity of the client system.

  • Client system files.
  • Unauthorized file transfer and execution.
  • System compromise or data manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that the ScreenConnect servers are unaffected and the vulnerability lies within the client during an active remote session, the primary responsibility for addressing this issue likely falls to teams managing endpoints and remote access solutions, such as endpoint security or IT operations. The immediate first step is to identify all instances of the ScreenConnect client, confirm if they are actively used and exposed, and then determine the accountable owner for these endpoints before planning remediation actions.

  • Endpoint security or IT operations teams own this.
  • Verify client usage and active session exposure.
  • Plan remediation based on endpoint inventory.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ScreenConnect and how is it used?

ScreenConnect is a remote support and access software suite used by IT professionals to manage computers, provide help-desk assistance, and perform remote maintenance. It operates using a server-client architecture, where the client software is installed on end-user machines to allow administrators to securely connect, view screens, and interact with the system remotely.

What does CWE-269 and CWE-862 mean for CVE-2026-84869?

These classifications refer to Improper Privilege Management (CWE-269) and Missing Authorization (CWE-862). In the context of this CVE, they mean the software fails to properly verify if a user has permission to perform specific actions. Specifically, the client allows file transfers and execution without checking for the required host authorization, which is a fundamental security control.

How does an attacker trigger this vulnerability?

The vulnerability requires an attacker to have authenticated access to an active remote session. It does not trigger via simple network reconnaissance or by targeting a server. If a session is not active or if an attacker cannot establish the necessary connection to the client, this specific path for file transfer and execution is not available.

Is my organization at risk according to Halo Surface Signal?

Halo Surface Signal indicates that exploitation is unlikely for most because this bug is restricted to active, established remote sessions. It is not an internet-facing gateway vulnerability. Risk is primarily concentrated where attackers have already gained the ability to interact with a client through a live session, rather than through opportunistic web-based attacks.

What should I do if I run ScreenConnect?

Begin by auditing your environment to identify every machine where the ScreenConnect client is installed. Since servers are unaffected, focus your investigation on endpoints managed by your IT or remote support teams. Verify which systems are currently utilizing the software, determine who is responsible for those assets, and prepare to deploy updates once guidance is available.

References