CVE-2026-9089

high

Description

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

References

https://www.connectwise.com/company/trust/security-bulletins/2026-05-21-connectwise-automate-bulletin

Details

Source: Mitre, NVD

Published: 2026-05-21

Updated: 2026-05-21

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High