Critical Analysis: CVE-2026-84869 - ConnectWise ScreenConnect Improper Privilege Management and ... — September 16, 2026
Published 16 Sep 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
September 16, 2026 Initial Discovery and Context Today, we're dissecting CVE-2026-84869, a critical improper privilege management and missing authorization vulnerability impacting ConnectWise ScreenConnect. This isn't just another arbitrary vulnerability; it represents a fundamental breakdown in trust boundaries within a widely deployed remote support and access solution. Discovered internally by a vigilant security researcher and subsequently reported to ConnectWise, this flaw was publicly disclosed today, earning a CVSSv3.1 score of 9.8 (CRITICAL) due to its pervasive impact and low attack complexity. Given ScreenConnect’s extensive footprint across Managed Service Providers (MSPs), internal IT departments, and large enterprise environments, the potential for widespread compromise is frankly, terrifying. This particular variant of privilege escalation affects ScreenConnect versions 23.