SB2026031932 - Insecure storage of machine keys in ScreenConnect
Published: March 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insecure storage of sensitive information (CVE-ID: CVE-2026-3564)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores unique machine keys per instance within server configuration files. A local user can extract such key and misuse it for session authentication
Remediation
Install update from vendor's website.