CVE-2026-0696: ConnectWise Professional Service Automation

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.

Affected products

  • ConnectWise Professional Service Automation: before 2026.1 (fixed in 2026.1)

Published 2026-01-16. Last modified 2026-06-17.