« Volver al listado

CVE-2026-9089

Estado: AnalizadaAlta (8.8)—

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A indica red adyacente; falta de verificación en componentes plugin (CWE-494) permite man-in-the-middle malicioso inyectar código en la cadena de suministro del agente Automate.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-9089",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-9089",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-21T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "7d616e1a-3288-43b1-a0dd-0a65d3e70a49",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "7d616e1a-3288-43b1-a0dd-0a65d3e70a49",
      "affectedData": [
        {
          "vendor": "ConnectWise",
          "modules": [
            "Agent"
          ],
          "product": "Automate",
          "versions": [
            {
              "status": "affected",
              "version": "All versions prior to 2026.5"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-21T16:16:23.570",
  "references": [
    {
      "url": "https://www.connectwise.com/company/trust/security-bulletins/2026-05-21-connectwise-automate-bulletin",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "7d616e1a-3288-43b1-a0dd-0a65d3e70a49"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "7d616e1a-3288-43b1-a0dd-0a65d3e70a49",
      "description": [
        {
          "lang": "en",
          "value": "CWE-494"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5."
    },
    {
      "lang": "es",
      "value": "El Agente de ConnectWise Automate™ no verifica completamente la autenticidad de los componentes obtenidos durante la carga de plugins y las operaciones de autoactualización. Este problema se aborda en Automate 2026.5."
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FA91E89-B0A8-4F5D-B262-923D2901827A",
              "versionEndExcluding": "2026.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "7d616e1a-3288-43b1-a0dd-0a65d3e70a49"
}