← Vulnerability feed

Vulnerability record · CVE-2020-15027 · published 16 July 2020

CVE-2020-15027: Connectwise automate improper authentication vulnerability

Connectwise · Automate

ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.

9.8 CVSS 3.1 Critical EPSS 1.3% · top 29.8% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15027 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35066Connectwise automate xml external entity (xxe) vulnerabilityAn XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.EPSS 1.1%8.8CVE-2026-9089Connectwise automate download of code without integrity check vulnerabilityThe ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This …EPSS 0.21%8.8CVE-2020-15838Connectwise automate incorrect permission assignment vulnerabilityThe Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.EPSS 1.2%8.1CVE-2023-47257Connectwise automate code injection vulnerabilityConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.EPSS 1.0%7.5CVE-2025-11493Connectwise automate download of code without integrity check vulnerabilityThe ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integra…EPSS 0.23%7.5CVE-2025-11492Connectwise automate cleartext transmission vulnerabilityIn the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man…EPSS 0.21%7.1CVE-2026-6066Connectwise automate cleartext transmission vulnerabilityConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert…EPSS 0.13%6.1CVE-2023-23126Connectwise automate clickjacking vulnerabilityConnectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended action…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2020-15027), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.