CVE-2026-11596
MEDIUMCVSS 4.7/10EPSS 0.22%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-11596?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
