---
id: CVE-2025-11493
title: >-
  The ConnectWise Automate Agent does not fully verify the authenticity of files
  downloaded from the server, such as updates, dependencies, and integrations
summary: >-
  The ConnectWise Automate Agent does not fully verify the authenticity of files
  downloaded from the server, such as updates, dependencies, and integrations.
  This creates a risk where an on-path attacker could perform a
  man-in-the-middle a…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-494
vendor: connectwise
product: automate
affected:
  - automate < 2025.9
patched:
  - automate 2025.9
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11493'
references:
  - url: >-
      https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fix
    label: 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
tags:
  - nvd
epss: 0.00227
epssPercentile: 0.12397
ingestedAt: '2026-10-09T12:53:29.093Z'
---

## Overview

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by impersonating a legitimate server. This risk is mitigated when HTTPS is enforced and is related to CVE-2025-11492.

## Affected

- `automate < 2025.9`

## Remediation

Upgrade past the affected range:

- `automate 2025.9`
