CVE-2026-0696
EUVD-2026-294316.01.2026, 14:15
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| connectwise | professional_service_automation | 𝑥 < 2026.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration