GBHackers

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions


ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments.

In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier.

The advisory, released on September 3, 2026, highlights file-transfer permissions as the main area of concern. Although ConnectWise has not yet provided technical details about the underlying flaw, it confirmed that organizations using CW Remote Access should review and restrict technician file-transfer capabilities until a permanent solution is available.

Affected Systems

The advisory applies to ScreenConnect Remote Access, which includes both Support and Access session types. This means that managed service providers (MSPs), IT administrators, and enterprise teams using ScreenConnect in either ConnectWise cloud environments or self-hosted infrastructure may be impacted.

ScreenConnect is widely utilized by MSPs and support teams to manage endpoints remotely, troubleshoot systems, and transfer files during remote assistance sessions.

Because the issue concerns guest file-transfer behavior, incorrectly configured roles could pose security risks in environments where technicians are allowed to upload or download files during active remote sessions.

ConnectWise has not yet confirmed whether the issue has been exploited in the wild, nor has it disclosed attack prerequisites, affected versions, or the specific technical impacts.

The absence of a CVE identifier means that defenders should closely monitor ConnectWise’s advisory page for updated indicators, version information, and remediation guidance.

Until a patched version is released, ConnectWise recommends that organizations disable file-transfer permissions for technician roles. This mitigation does not require an upgrade to ScreenConnect and can be implemented immediately through the product’s Administration interface.

Administrators should follow these steps:

  • Log in to the Administration page of the ScreenConnect instance.
  • Navigate to Administration > Security > Roles.
  • Edit each role assigned to ScreenConnect users.
  • Review every session group with assigned permissions, shown in bold text.
  • In the Scoped Permissions window, locate the TransferFiles permission.
  • For legacy ScreenConnect versions, check for TransferFilesInSession.
  • Deselect the relevant file-transfer permission and save the updated role.
  • Repeat the process for all defined roles and applicable session groups.

Turning off these permissions will prevent technicians from transferring files during remote sessions. Organizations should consider the operational impact before implementing this mitigation, especially when file exchange is necessary for software deployment, incident response, log collection, or remote troubleshooting workflows.

ConnectWise plans to issue a CVE identifier following the rollout of changes across its cloud environments. A patched version addressing the underlying file-transfer behavior is expected to be released within a week, along with updated vendor guidance.

Security teams should prioritize reviewing configurations based on this advisory. Remote access platforms are high-value targets because they provide direct access to managed endpoints and typically operate with elevated privileges.

Restricting unnecessary file-transfer capabilities can help reduce the risks of unauthorized payload delivery, data exfiltration, or misuse of remote support sessions while waiting for a fix.

Organizations should also document any changes to roles, notify service desk teams of temporary restrictions, and prepare to test and deploy the upcoming ScreenConnect update as soon as ConnectWise publishes it.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection



Source link