No analysis available yet.
Vendor Solution
Cloud Cloud instances are automatically being updated to the latest ConnectWise PSA release. On-premise Apply the 2026.1 release patches and ensure all desktop clients are up to date.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 27 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 23 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Connectwise professional Service Automation
|
|
| CPEs | cpe:2.3:a:connectwise:professional_service_automation:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Connectwise professional Service Automation
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Connectwise
Connectwise psa |
|
| Vendors & Products |
Connectwise
Connectwise psa |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values. | |
| Title | Session Cookies Missing HttpOnly Attribute | |
| Weaknesses | CWE-1004 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ConnectWise
Published:
Updated: 2026-01-27T12:14:05.158Z
Reserved: 2026-01-07T21:32:00.544Z
Link: CVE-2026-0696
Updated: 2026-01-16T14:07:01.298Z
Status : Modified
Published: 2026-01-16T14:15:54.940
Modified: 2026-01-27T13:15:54.403
Link: CVE-2026-0696
No data.
OpenCVE Enrichment
Updated: 2026-01-19T09:20:48Z