Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDefault status
unaffected
All versions prior to 2026.1
affected
Description
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
Problem types
CWE-1004 Sensitive Cookie Without 'HttpOnly' Flag
Product status
All versions prior to 2026.1
Credits
Petar Sever (The Missing Link)
References
www.connectwise.com/...bulletins/2026-01-15-psa-security-fix
www.themissinglink.com.au/security-advisories/cve-2026-0696