CVE-2026-6066 is an unencrypted communication vulnerability in ConnectWise Automate's Solution Center that allows certain client-to-server traffic to traverse the network without transport-layer encryption, potentially exposing sensitive data to interception attacks. The vulnerability affects Automate deployments prior to version 2026.4, where the issue has been remediated through enforcement of secure communication protocols. The vulnerability carries a CVSS 3.1 score of 7.1 (HIGH) with a network-based attack vector requiring low complexity and authenticated user privileges. The primary impact is confidentiality compromise (high severity) with minor integrity risk, while availability remains unaffected. The attack requires no user interaction once an authenticated session is established. Current exploitation status indicates minimal community attention and no active weaponization. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00013 reflects extremely low probability of exploitation in the wild. Organizations running Automate versions prior to 2026.4 should prioritize patching to eliminate the unencrypted communication pathway.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.4CPE matchmatch criteria | cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.