VulnerabilityModified
CVE-2026-0696
In some scenarios, this could allow client-side scripts access to session cookie values.
MEDIUM 6.5EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1004
- Affected
- connectwise/professional service automation
- Source
- 7d616e1a-3288-43b1-a0dd-0a65d3e70a49
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.