CVE-2026-9089

high
Published 2026-05-21 · Modified 2026-05-22
CVSS v3
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49 — https://www.connectwise.com/company/trust/security-bulletins/2026-05-21-connectwise-automate-bulletin

Application impact

VendorProductVersionsFixed
connectwiseautomate{"endExcluding":"2026.5"}2026.5

References

CWEs

CWE-494

Verify integrity in audit chain (admin only). AS-IS.