← Vulnerability feed

Vulnerability record · CVE-2023-23126 · published 1 February 2023

CVE-2023-23126: Connectwise automate clickjacking vulnerability

Connectwise · Automate

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

6.1 CVSS 3.1 Medium EPSS 0.37% · top 71.2% CWE-1021 · Clickjacking
6.1CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23126 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35066Connectwise automate xml external entity (xxe) vulnerabilityAn XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.EPSS 1.1%9.8CVE-2020-15027Connectwise automate improper authentication vulnerabilityConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem…EPSS 1.3%8.8CVE-2026-9089Connectwise automate download of code without integrity check vulnerabilityThe ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This …EPSS 0.21%8.8CVE-2020-15838Connectwise automate incorrect permission assignment vulnerabilityThe Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.EPSS 1.2%8.1CVE-2023-47257Connectwise automate code injection vulnerabilityConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.EPSS 1.0%7.5CVE-2025-11493Connectwise automate download of code without integrity check vulnerabilityThe ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integra…EPSS 0.23%7.5CVE-2025-11492Connectwise automate cleartext transmission vulnerabilityIn the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man…EPSS 0.21%7.1CVE-2026-6066Connectwise automate cleartext transmission vulnerabilityConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert…EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2023-23126), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.