Session Cookie Vulnerability in ConnectWise PSA by ConnectWise
CVE-2026-0696

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 January 2026

What is CVE-2026-0696?

In versions of ConnectWise PSA prior to 2026.1, certain session cookies lacked the HttpOnly attribute, which can lead to potential exposure of sensitive session information to client-side scripts. This vulnerability underscores the importance of secure cookie management practices to safeguard user sessions from unauthorized access.

Affected Version(s)

PSA All versions prior to 2026.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Petar Sever (The Missing Link)
.