A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.