CVE-2025-11492
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.20%
- CWE
- CWE-319
- Published
- 2025-10-16
- Last modified
- 2026-03-12
Affected products
- ConnectWise Automate
Weakness type
Related vulnerabilities
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-81330 — Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information
- CVE-2026-87482 — Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to...
- CVE-2026-71216 — Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
- CVE-2026-84381 — HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
- CVE-2026-84366 — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
- CVE-2026-55860 — MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
- CVE-2026-55857 — MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials